CAS-004 Security Engineering Practice Question
A security engineer is deploying a new wireless network for a corporate campus and must ensure that all client traffic is protected with strong encryption and that the network does not rely on a pre-shared key. Which configuration should the engineer implement?
⚠ Common exam trap
The trap here is assuming that rotating a pre-shared key converts WPA2-Personal into an enterprise-grade solution, when the fundamental shared-secret exposure remains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA3-Enterprise with 802.1X authentication against a RADIUS server
WPA3-Enterprise with 802.1X and RADIUS authentication meets both requirements: it provides strong, current cryptographic protections and authenticates each client individually, so no pre-shared key is used. WPA2-Personal retains a shared key, open authentication provides no encryption, and WEP is broken. The enterprise mode with 802.1X is the standard choice for corporate wireless deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPA2-Personal with a rotated pre-shared key every 30 days
Why it's wrong here
WPA2-Personal still relies on a pre-shared key that is shared among all clients, so rotating it periodically does not eliminate the shared-secret weakness and creates operational overhead. Every device that knows the current key can derive the pairwise master key and potentially decrypt other clients' traffic. This does not meet the requirement to avoid a pre-shared key.
- ✗
WEP with 128-bit keys and MAC address filtering
Why it's wrong here
WEP is cryptographically broken and can be cracked within minutes regardless of key length, and it uses a shared static key. MAC address filtering is trivially bypassed by spoofing. This configuration provides neither strong encryption nor the absence of a pre-shared key, and it would fail any modern wireless security assessment.
- ✓
WPA3-Enterprise with 802.1X authentication against a RADIUS server
Why this is correct
WPA3-Enterprise uses 802.1X with EAP to authenticate each user or device against a RADIUS server, eliminating the shared-secret weakness of pre-shared keys. It also mandates stronger cryptographic protections, including protected management frames and, in WPA3-Enterprise 192-bit mode, GCMP-256 and SHA-384. This directly satisfies the requirement for strong encryption without a pre-shared key.
- ✗
Open authentication with a captive portal for guest access
Why it's wrong here
Open authentication provides no link-layer encryption at all, leaving over-the-air traffic readable by anyone within range. A captive portal is an application-layer access control and does not encrypt the wireless medium. This configuration fails the strong-encryption requirement entirely and is unsuitable for corporate campus traffic.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.