Courseiva
mediumMultiple SelectObjective-mapped

CAS-004 Practice Question: Is designing a secure wireless network for a…

A security engineer is designing a secure wireless network for a corporate office. Which TWO configurations should be implemented to maximize security?

⚠ Common exam trap

CompTIA often tests the misconception that disabling SSID broadcast or using MAC filtering provides meaningful security, when in reality these are trivial to bypass and do not address the core requirements of authentication and encryption in a corporate wireless network.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

WPA3-Enterprise

WPA3-Enterprise (Option B) is correct because it provides the highest level of wireless security by mandating the use of Simultaneous Authentication of Equals (SAE) for key exchange, which eliminates pre-shared key vulnerabilities and offers forward secrecy. It also supports 192-bit cryptographic strength when using CNSA Suite mode, making it resistant to offline dictionary attacks and brute-force attempts, which is essential for a corporate environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • WPA2-PSK

    Why it's wrong here

    WPA2-PSK is susceptible to dictionary attacks and does not offer per-user authentication.

  • WPA3-Enterprise

    Why this is correct

    WPA3-Enterprise provides stronger encryption and authentication than WPA2.

  • MAC address filtering

    Why it's wrong here

    MAC addresses can be spoofed, providing minimal security.

  • 802.1X with EAP-TLS

    Why this is correct

    EAP-TLS uses certificates for mutual authentication, eliminating password vulnerabilities.

  • Disable SSID broadcast

    Why it's wrong here

    Disabling SSID broadcast is easily circumvented by attackers and not a security control.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.