CAS-004 Security Engineering Practice Question
A security engineer is deploying a wireless network for a corporate campus that must authenticate users with 802.1X and protect credentials from eavesdropping. The engineer configures a RADIUS server and WPA3-Enterprise. Which TWO additional configuration elements are required to establish a mutually authenticated, encrypted EAP tunnel before the supplicant's identity is exposed? (Choose two.)
⚠ Common exam trap
Candidates often confuse WPA3-SAE, a personal-mode passphrase method, with WPA3-Enterprise 802.1X, which relies on certificates and a tunneling EAP method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An EAP method that establishes a TLS tunnel before transmitting the inner identity, such as EAP-TTLS or PEAP.
A protected EAP deployment needs the supplicant to validate the authentication server via a trusted certificate, then negotiate a TLS tunnel in which the real identity and credentials travel. PEAP and EAP-TTLS both do this, whereas methods that expose identity before tunneling do not. Together the trusted server certificate and the tunneling EAP method deliver mutual authentication and credential protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
An EAP method that establishes a TLS tunnel before transmitting the inner identity, such as EAP-TTLS or PEAP.
Why this is correct
EAP-TTLS and PEAP create an encrypted TLS tunnel using the server certificate, and the actual user identity and credentials are exchanged inside that tunnel. This protects the supplicant identity from passive eavesdroppers and prevents credential theft. A method that sends identity in the clear before the tunnel, such as EAP-MD5, does not meet the requirement.
- ✗
A preshared key distributed to all campus clients through group policy.
Why it's wrong here
A preshared key is used in personal wireless modes and is shared by every client, so it provides no per-user identity and no mutual authentication. It cannot establish an EAP tunnel between supplicant and RADIUS server. Distributing it via group policy also means a single leaked key compromises the whole network, which is why it is inappropriate here.
- ✓
A server certificate issued by an internal CA and trusted by the supplicants.
Why this is correct
Mutual authentication requires the supplicant to validate the authentication server, which it does by verifying the RADIUS server's certificate against a trusted CA. Without a trusted server certificate, the supplicant cannot confirm it is talking to the legitimate authentication server, and the tunnel is vulnerable to an evil twin. This certificate is a prerequisite for the protected EAP exchange.
- ✗
WPA3-SAE on the access point to derive the pairwise master key from the passphrase.
Why it's wrong here
WPA3-SAE is the simultaneous authentication of equals used in personal mode, where clients share a passphrase. In an 802.1X enterprise deployment with a RADIUS server, the pairwise master key is derived from the EAP exchange, not from a passphrase. Enabling SAE would not establish the protected EAP tunnel and conflicts with enterprise authentication.
- ✗
A captive portal that redirects unauthenticated clients to a credential entry page.
Why it's wrong here
A captive portal is a web-based interception mechanism typically used for guest access or web authentication, not for 802.1X EAP tunneling. It does not create an encrypted EAP tunnel or perform mutual certificate authentication. Adding a portal would not satisfy the requirement and could even expose credentials through an unencrypted web form.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.