Courseiva
Security Engineering →hardMultiple Choice

CAS-004 Security Engineering Practice Question

A security engineer is configuring a wireless network for a hospital. The network must support legacy medical devices that only support WPA2-Personal with pre-shared keys (PSK) and cannot be upgraded. The hospital also wants to prevent unauthorized devices from connecting and to detect rogue access points. Which of the following should the engineer implement to BEST meet these requirements?

⚠ Common exam trap

The trap here is assuming that the most secure option (WPA3-Enterprise) is always best, but compatibility with legacy devices is a hard constraint that must be respected.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA2-Personal with a strong, unique PSK and a wireless intrusion prevention system (WIPS).

WPA2-Personal with a strong PSK accommodates legacy devices that cannot use 802.1X. A WIPS monitors the airwaves for rogue access points and can detect and mitigate unauthorized devices. This combination meets the requirements without requiring device upgrades, balancing compatibility and security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPA2-Enterprise with 802.1X authentication and a RADIUS server.

    Why it's wrong here

    WPA2-Enterprise with 802.1X requires supplicant support on the devices. Legacy medical devices that only support WPA2-Personal with PSK cannot authenticate via 802.1X. Therefore, this option is not feasible for those devices, even though it offers strong security and rogue AP detection through RADIUS logs.

  • ✗

    Open network with a captive portal and MAC address filtering.

    Why it's wrong here

    An open network with a captive portal does not provide encryption, leaving data in transit vulnerable. MAC address filtering is easily bypassed by spoofing. This option fails to meet the requirement for preventing unauthorized devices and does not secure the wireless traffic, making it a poor choice for a hospital.

  • ✗

    WPA3-Enterprise with 192-bit mode and a RADIUS server.

    Why it's wrong here

    WPA3-Enterprise is not supported by legacy devices that only support WPA2-Personal. It also requires 802.1X, which these devices lack. While it provides strong security, it is incompatible with the stated constraints, making it an invalid choice for this scenario.

  • ✓

    WPA2-Personal with a strong, unique PSK and a wireless intrusion prevention system (WIPS).

    Why this is correct

    WPA2-Personal with a strong PSK accommodates legacy devices that cannot use 802.1X. A WIPS monitors the airwaves for rogue access points and can detect and mitigate unauthorized devices. This combination meets the requirements without requiring device upgrades, balancing compatibility and security.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.