FC0-U71 Security Practice Question
A small accounting firm's wireless network currently uses WPA2-Personal with a shared passphrase that all 20 employees know. The office manager reports that a former contractor who was given the passphrase can still connect to the Wi-Fi from the parking lot. The firm wants each user to authenticate with their own unique credentials and wants to be able to revoke access for one person without disrupting everyone else. Which wireless security method should the firm implement?
⚠ Common exam trap
The trap here is assuming that moving from WPA2-Personal to WPA3-Personal fixes shared-credential problems, when WPA3-Personal still uses one passphrase for all users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA2-Enterprise with 802.1X authentication against a RADIUS server
The firm needs two things a shared passphrase cannot provide: distinct credentials per person and the ability to cut off one account without rekeying the whole office. WPA2-Enterprise pairs 802.1X with a RADIUS server so each login is validated individually against a directory, and disabling the contractor's account instantly blocks that person. Personal modes, MAC filtering, and WPS all rely on a network-wide secret or device identifiers rather than user identity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MAC address filtering on the wireless access point
Why it's wrong here
MAC address filtering only permits listed hardware addresses, but the contractor could spoof the MAC of a known allowed device, and MAC addresses are not user credentials. Managing an allow list of 20 devices also creates administrative overhead and still requires a shared passphrase for encryption. It fails to provide unique per-user authentication or clean revocation of one person.
- ✗
Wi-Fi Protected Setup (WPS) with push-button configuration for each employee
Why it's wrong here
WPS is designed to simplify joining a network by pushing a button or entering a PIN, and it actually weakens security because the PIN method is vulnerable to brute-force attacks. It does not introduce individual user accounts or a central authentication service. Enabling WPS would leave the shared-passphrase problem in place and add new risk instead of solving the revocation issue.
- ✓
WPA2-Enterprise with 802.1X authentication against a RADIUS server
Why this is correct
WPA2-Enterprise uses IEEE 802.1X so each user authenticates with individual credentials validated by a RADIUS server, and the firm can disable just the former contractor's account. The shared passphrase problem disappears because no pre-shared key is distributed to clients. This directly satisfies both requirements: unique per-user credentials and selective, non-disruptive revocation.
- ✗
WPA3-Personal with Simultaneous Authentication of Equals (SAE)
Why it's wrong here
WPA3-Personal with SAE strengthens the handshake against offline dictionary attacks, but it is still a personal mode built around one shared passphrase for the whole network. Every employee and the contractor would continue using the same secret, so the firm could not revoke only the contractor. It does not deliver per-user credentials, which is the core requirement described.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.