N10-009 Network Implementation Practice Question
A company wants to deploy a wireless network for employee devices using the highest security standard. The network will use a RADIUS server for authentication. Which authentication method should be configured?
⚠ Common exam trap
Watch out — candidates often confuse WPA3-SAE (which is indeed more secure than WPA2-PSK) with enterprise authentication, but SAE still uses a shared passphrase and cannot integrate with a RADIUS server for per-user authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
802.1X/EAP
B is correct because 802.1X/EAP is the only option that provides enterprise-grade authentication using a RADIUS server. It requires each user to present unique credentials (e.g., username/password or certificate), which are verified by the RADIUS server before granting network access. This meets the requirement for the highest security standard in a corporate environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPA3-SAE
Why it's wrong here
While WPA3-SAE (Simultaneous Authentication of Equals) significantly enhances security over WPA2-PSK by protecting against offline dictionary attacks, it operates using a single pre-shared key for all clients. This fundamental design means it functions as a Personal mode, lacking the centralized, per-user authentication and authorization capabilities provided by a RADIUS server. Consequently, it is unsuitable for enterprise-grade deployments requiring individual user accountability and granular access control.
When this WOULD be correct
If the question asked for the highest security standard for a small office/home office (SOHO) network without a RADIUS server, or for a network using only a pre-shared key, WPA3-SAE would be the correct answer.
- ✓
802.1X/EAP
Why this is correct
802.1X/EAP is the industry standard for enterprise wireless security, leveraging a RADIUS server for centralized authentication and authorization. This architecture enables robust per-user access control and dynamic key management, supporting various EAP methods like PEAP or EAP-TLS. It provides strong, individualized encryption keys and accountability, which is crucial for securing employee devices in a corporate environment demanding the highest security.
- ✗
WPA2-PSK
Why it's wrong here
WPA2-PSK relies on a single, static pre-shared key for all wireless clients, which, if compromised, grants unauthorized access to the entire network segment. This method inherently lacks individual user accountability and the dynamic key generation provided by 802.1X/EAP. It is inadequate for securing employee devices in an environment demanding high security, centralized management, and granular access control, making it a less secure option for enterprises.
When this WOULD be correct
In a small office/home office (SOHO) scenario where no RADIUS server is available and ease of setup is prioritized over highest security, WPA2-PSK would be the correct choice.
- ✗
WEP with RADIUS
Why it's wrong here
WEP (Wired Equivalent Privacy) is an obsolete encryption protocol with severe cryptographic vulnerabilities, including a small Initialization Vector (IV) and weak key scheduling, making it easily crackable. Even when combined with a RADIUS server for authentication, WEP's fundamental encryption flaws expose all transmitted data to interception and decryption. This renders it completely unsuitable for any secure network, regardless of the authentication backend, and certainly not for deploying the highest security for employee devices.
When this WOULD be correct
If the question asked for a legacy authentication method that uses a RADIUS server for key distribution in a WEP-based network, then 'WEP with RADIUS' could be correct, though it would still be insecure.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓802.1X/EAPCorrect answer▾
Why this is correct
802.1X/EAP is the industry standard for enterprise wireless security, leveraging a RADIUS server for centralized authentication and authorization. This architecture enables robust per-user access control and dynamic key management, supporting various EAP methods like PEAP or EAP-TLS. It provides strong, individualized encryption keys and accountability, which is crucial for securing employee devices in a corporate environment demanding the highest security.
✗WPA3-SAEWrong answer — click to see why▾
Why this is wrong here
WPA3-SAE is a personal authentication mode that uses a shared password, not a RADIUS server. The question specifies using a RADIUS server for authentication, which requires an enterprise mode like 802.1X/EAP.
★ When this WOULD be the correct answer
If the question asked for the highest security standard for a small office/home office (SOHO) network without a RADIUS server, or for a network using only a pre-shared key, WPA3-SAE would be the correct answer.
Why candidates choose this
Candidates may know WPA3 is the latest Wi-Fi security standard and assume it is always the best choice, overlooking that SAE is a personal mode and does not integrate with RADIUS.
✗WPA2-PSKWrong answer — click to see why▾
Why this is wrong here
WPA2-PSK uses a pre-shared key for authentication, not a RADIUS server, so it does not meet the requirement for enterprise-grade authentication with a RADIUS server.
★ When this WOULD be the correct answer
In a small office/home office (SOHO) scenario where no RADIUS server is available and ease of setup is prioritized over highest security, WPA2-PSK would be the correct choice.
Why candidates choose this
Candidates may confuse WPA2-PSK with WPA2-Enterprise, or assume that PSK can be used with RADIUS, because both involve a password but the authentication mechanism differs.
✗WEP with RADIUSWrong answer — click to see why▾
Why this is wrong here
WEP with RADIUS is not a valid authentication method; WEP uses static keys or RADIUS for key distribution but is inherently insecure and does not meet 'highest security standard'.
★ When this WOULD be the correct answer
If the question asked for a legacy authentication method that uses a RADIUS server for key distribution in a WEP-based network, then 'WEP with RADIUS' could be correct, though it would still be insecure.
Why candidates choose this
Candidates may see 'RADIUS' and assume any combination with it is secure, overlooking that WEP is outdated and broken.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Wireless Standards and Configuration
Key term
802.1X
802.1X is a network access control standard that authenticates devices before they are allowed to connect to a wired or wireless network.
Key term
Extensible Authentication Protocol
Extensible Authentication Protocol (EAP) is a flexible authentication framework used in network access control, particularly in wireless and point-to-point connections, that supports multiple authentication methods without requiring changes to the underlying protocol.
About these practice questions
Courseiva writes every N10-009 question from scratch — 464 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.