mediumMultiple SelectObjective-mapped
CAS-004 Practice Question: Is designing a secure wireless network for a…
A security engineer is designing a secure wireless network for a corporate office. Which TWO configurations should be implemented to maximize security?
⚠ Common exam trap
CompTIA often tests the misconception that disabling SSID broadcast or using MAC filtering provides meaningful security, when in reality these are trivial to bypass and do not address the core requirements of authentication and encryption in a corporate wireless network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA3-Enterprise
WPA3-Enterprise (Option B) is correct because it provides the highest level of wireless security by mandating the use of Simultaneous Authentication of Equals (SAE) for key exchange, which eliminates pre-shared key vulnerabilities and offers forward secrecy. It also supports 192-bit cryptographic strength when using CNSA Suite mode, making it resistant to offline dictionary attacks and brute-force attempts, which is essential for a corporate environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPA2-PSK
Why it's wrong here
WPA2-PSK is susceptible to dictionary attacks and does not offer per-user authentication.
- ✓
WPA3-Enterprise
Why this is correct
WPA3-Enterprise provides stronger encryption and authentication than WPA2.
- ✗
MAC address filtering
Why it's wrong here
MAC addresses can be spoofed, providing minimal security.
- ✓
802.1X with EAP-TLS
Why this is correct
EAP-TLS uses certificates for mutual authentication, eliminating password vulnerabilities.
- ✗
Disable SSID broadcast
Why it's wrong here
Disabling SSID broadcast is easily circumvented by attackers and not a security control.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.