Courseiva
Security Engineering →easyMultiple Choice

CAS-004 Security Engineering Practice Question

A security engineer is deploying a new wireless network for a corporate campus and must ensure that all client traffic is protected with strong encryption and that the network does not rely on a pre-shared key. Which configuration should the engineer implement?

⚠ Common exam trap

The trap here is assuming that rotating a pre-shared key converts WPA2-Personal into an enterprise-grade solution, when the fundamental shared-secret exposure remains.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA3-Enterprise with 802.1X authentication against a RADIUS server

WPA3-Enterprise with 802.1X and RADIUS authentication meets both requirements: it provides strong, current cryptographic protections and authenticates each client individually, so no pre-shared key is used. WPA2-Personal retains a shared key, open authentication provides no encryption, and WEP is broken. The enterprise mode with 802.1X is the standard choice for corporate wireless deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPA2-Personal with a rotated pre-shared key every 30 days

    Why it's wrong here

    WPA2-Personal still relies on a pre-shared key that is shared among all clients, so rotating it periodically does not eliminate the shared-secret weakness and creates operational overhead. Every device that knows the current key can derive the pairwise master key and potentially decrypt other clients' traffic. This does not meet the requirement to avoid a pre-shared key.

  • ✗

    WEP with 128-bit keys and MAC address filtering

    Why it's wrong here

    WEP is cryptographically broken and can be cracked within minutes regardless of key length, and it uses a shared static key. MAC address filtering is trivially bypassed by spoofing. This configuration provides neither strong encryption nor the absence of a pre-shared key, and it would fail any modern wireless security assessment.

  • ✓

    WPA3-Enterprise with 802.1X authentication against a RADIUS server

    Why this is correct

    WPA3-Enterprise uses 802.1X with EAP to authenticate each user or device against a RADIUS server, eliminating the shared-secret weakness of pre-shared keys. It also mandates stronger cryptographic protections, including protected management frames and, in WPA3-Enterprise 192-bit mode, GCMP-256 and SHA-384. This directly satisfies the requirement for strong encryption without a pre-shared key.

  • ✗

    Open authentication with a captive portal for guest access

    Why it's wrong here

    Open authentication provides no link-layer encryption at all, leaving over-the-air traffic readable by anyone within range. A captive portal is an application-layer access control and does not encrypt the wireless medium. This configuration fails the strong-encryption requirement entirely and is unsuitable for corporate campus traffic.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.