N10-009 Network Implementation Practice Question
A network administrator wants to allow wireless clients to seamlessly roam between access points without re-authenticating to the RADIUS server for each transition. Which IEEE standard should be implemented?
⚠ Common exam trap
CompTIA often tests the distinction between 802.11k (which helps clients decide where to roam) and 802.11r (which speeds up the actual authentication process), leading candidates to confuse 'neighbor reports' with 'fast roaming authentication'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
802.11r
802.11r, also known as Fast BSS Transition (FT), enables wireless clients to roam between access points without re-authenticating to the RADIUS server by using a cached Pairwise Master Key (PMK) and performing a faster, over-the-air or over-the-DS key exchange. This reduces the time required for roaming handoffs, which is critical for real-time applications like VoIP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
802.11r
Why this is correct
IEEE 802.11r, also known as Fast BSS Transition (FT), is specifically designed to enable seamless and rapid roaming for wireless clients between access points within the same Extended Service Set (ESS). It achieves this by allowing clients to pre-authenticate with target APs or by using a faster key exchange mechanism, significantly reducing the authentication latency that would otherwise disrupt real-time applications like VoIP. This standard minimizes the time a client is disconnected during a handoff, ensuring a smooth user experience.
- ✗
802.11k
Why it's wrong here
IEEE 802.11k, or Radio Resource Measurement, enhances roaming efficiency by providing wireless clients with information about neighboring access points. This standard allows clients to request and receive neighbor reports, which include details like channel utilization and available bandwidth, helping the client make a more informed decision about which AP to associate with. However, 802.11k itself does not handle the authentication process or accelerate the transition; it merely provides data to aid client selection.
When this WOULD be correct
A network administrator wants to improve client roaming efficiency by enabling clients to discover nearby access points and optimize channel selection. Which IEEE standard should be implemented?
- ✗
802.11w
Why it's wrong here
IEEE 802.11w, also known as Protected Management Frames (PMF), is designed to enhance the security of wireless networks by protecting critical management frames from tampering and spoofing attacks. It encrypts and integrity-protects frames such as deauthentication, disassociation, and robust action frames, preventing denial-of-service attacks and unauthorized disconnections. While vital for network stability and security, 802.11w does not directly facilitate or accelerate the client roaming process itself; its focus is on frame integrity.
When this WOULD be correct
A question asks: 'Which IEEE standard enhances wireless security by protecting management frames from forgery and eavesdropping?' In that context, 802.11w (Protected Management Frames) would be the correct answer.
- ✗
802.1X
Why it's wrong here
IEEE 802.1X is a port-based network access control standard primarily used for initial authentication of devices connecting to a network, both wired and wireless. It provides a robust framework for authenticating users or devices before granting network access, often leveraging EAP methods with a RADIUS server. While crucial for secure network entry, 802.1X does not inherently include mechanisms to accelerate the re-authentication process when a client roams between different access points, making it unsuitable for seamless fast roaming on its own.
When this WOULD be correct
A question asking for the standard that provides port-based network access control for both wired and wireless networks, typically used with EAP methods for authentication, would have 802.1X as the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓802.11rCorrect answer▾
Why this is correct
IEEE 802.11r, also known as Fast BSS Transition (FT), is specifically designed to enable seamless and rapid roaming for wireless clients between access points within the same Extended Service Set (ESS). It achieves this by allowing clients to pre-authenticate with target APs or by using a faster key exchange mechanism, significantly reducing the authentication latency that would otherwise disrupt real-time applications like VoIP. This standard minimizes the time a client is disconnected during a handoff, ensuring a smooth user experience.
✗802.11kWrong answer — click to see why▾
Why this is wrong here
802.11k provides neighbor reports and radio resource management to assist roaming decisions, but it does not eliminate the need for re-authentication to the RADIUS server during transitions.
★ When this WOULD be the correct answer
A network administrator wants to improve client roaming efficiency by enabling clients to discover nearby access points and optimize channel selection. Which IEEE standard should be implemented?
Why candidates choose this
Candidates may confuse 802.11k's roaming assistance features with the fast roaming capabilities of 802.11r, assuming it handles authentication offload.
✗802.11wWrong answer — click to see why▾
Why this is wrong here
802.11w is designed for management frame protection, not for seamless roaming or reducing re-authentication overhead. It does not address the requirement of avoiding RADIUS re-authentication during roaming.
★ When this WOULD be the correct answer
A question asks: 'Which IEEE standard enhances wireless security by protecting management frames from forgery and eavesdropping?' In that context, 802.11w (Protected Management Frames) would be the correct answer.
Why candidates choose this
Candidates may confuse 802.11w with roaming-related standards because both involve wireless client transitions, or they might think 'w' stands for 'wireless' or 'wandering'.
✗802.1XWrong answer — click to see why▾
Why this is wrong here
802.1X is an authentication framework used for port-based network access control, not a standard for seamless roaming. It requires re-authentication when transitioning between access points, which contradicts the goal of avoiding re-authentication.
★ When this WOULD be the correct answer
A question asking for the standard that provides port-based network access control for both wired and wireless networks, typically used with EAP methods for authentication, would have 802.1X as the correct answer.
Why candidates choose this
Candidates may confuse 802.1X with the roaming standards because it is commonly used in wireless security, leading them to think it handles roaming transitions.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Wireless Standards and Configuration
Key term
Voice over IP
Voice over IP (VoIP) is a technology that lets you make phone calls using an internet connection instead of a traditional telephone line.
Key term
BSSID
A BSSID is the MAC address of an access point's radio interface, uniquely identifying a wireless cell in a WLAN.
About these practice questions
One of 464 original N10-009 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.