Courseiva
Security →mediumMultiple Choice

FC0-U71 Security Practice Question

A small accounting firm's wireless network currently uses WPA2-Personal with a shared passphrase that all 20 employees know. The office manager reports that a former contractor who was given the passphrase can still connect to the Wi-Fi from the parking lot. The firm wants each user to authenticate with their own unique credentials and wants to be able to revoke access for one person without disrupting everyone else. Which wireless security method should the firm implement?

⚠ Common exam trap

The trap here is assuming that moving from WPA2-Personal to WPA3-Personal fixes shared-credential problems, when WPA3-Personal still uses one passphrase for all users.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA2-Enterprise with 802.1X authentication against a RADIUS server

The firm needs two things a shared passphrase cannot provide: distinct credentials per person and the ability to cut off one account without rekeying the whole office. WPA2-Enterprise pairs 802.1X with a RADIUS server so each login is validated individually against a directory, and disabling the contractor's account instantly blocks that person. Personal modes, MAC filtering, and WPS all rely on a network-wide secret or device identifiers rather than user identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MAC address filtering on the wireless access point

    Why it's wrong here

    MAC address filtering only permits listed hardware addresses, but the contractor could spoof the MAC of a known allowed device, and MAC addresses are not user credentials. Managing an allow list of 20 devices also creates administrative overhead and still requires a shared passphrase for encryption. It fails to provide unique per-user authentication or clean revocation of one person.

  • ✗

    Wi-Fi Protected Setup (WPS) with push-button configuration for each employee

    Why it's wrong here

    WPS is designed to simplify joining a network by pushing a button or entering a PIN, and it actually weakens security because the PIN method is vulnerable to brute-force attacks. It does not introduce individual user accounts or a central authentication service. Enabling WPS would leave the shared-passphrase problem in place and add new risk instead of solving the revocation issue.

  • ✓

    WPA2-Enterprise with 802.1X authentication against a RADIUS server

    Why this is correct

    WPA2-Enterprise uses IEEE 802.1X so each user authenticates with individual credentials validated by a RADIUS server, and the firm can disable just the former contractor's account. The shared passphrase problem disappears because no pre-shared key is distributed to clients. This directly satisfies both requirements: unique per-user credentials and selective, non-disruptive revocation.

  • ✗

    WPA3-Personal with Simultaneous Authentication of Equals (SAE)

    Why it's wrong here

    WPA3-Personal with SAE strengthens the handshake against offline dictionary attacks, but it is still a personal mode built around one shared passphrase for the whole network. Every employee and the contractor would continue using the same secret, so the firm could not revoke only the contractor. It does not deliver per-user credentials, which is the core requirement described.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.