Courseiva
Network ImplementationhardMultiple ChoiceObjective-mapped

N10-009 Network Implementation Practice Question

A company wants to deploy a wireless network for employee devices using the highest security standard. The network will use a RADIUS server for authentication. Which authentication method should be configured?

⚠ Common exam trap

Watch out — candidates often confuse WPA3-SAE (which is indeed more secure than WPA2-PSK) with enterprise authentication, but SAE still uses a shared passphrase and cannot integrate with a RADIUS server for per-user authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

802.1X/EAP

B is correct because 802.1X/EAP is the only option that provides enterprise-grade authentication using a RADIUS server. It requires each user to present unique credentials (e.g., username/password or certificate), which are verified by the RADIUS server before granting network access. This meets the requirement for the highest security standard in a corporate environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • WPA3-SAE

    Why it's wrong here

    While WPA3-SAE (Simultaneous Authentication of Equals) significantly enhances security over WPA2-PSK by protecting against offline dictionary attacks, it operates using a single pre-shared key for all clients. This fundamental design means it functions as a Personal mode, lacking the centralized, per-user authentication and authorization capabilities provided by a RADIUS server. Consequently, it is unsuitable for enterprise-grade deployments requiring individual user accountability and granular access control.

    When this WOULD be correct

    If the question asked for the highest security standard for a small office/home office (SOHO) network without a RADIUS server, or for a network using only a pre-shared key, WPA3-SAE would be the correct answer.

  • 802.1X/EAP

    Why this is correct

    802.1X/EAP is the industry standard for enterprise wireless security, leveraging a RADIUS server for centralized authentication and authorization. This architecture enables robust per-user access control and dynamic key management, supporting various EAP methods like PEAP or EAP-TLS. It provides strong, individualized encryption keys and accountability, which is crucial for securing employee devices in a corporate environment demanding the highest security.

  • WPA2-PSK

    Why it's wrong here

    WPA2-PSK relies on a single, static pre-shared key for all wireless clients, which, if compromised, grants unauthorized access to the entire network segment. This method inherently lacks individual user accountability and the dynamic key generation provided by 802.1X/EAP. It is inadequate for securing employee devices in an environment demanding high security, centralized management, and granular access control, making it a less secure option for enterprises.

    When this WOULD be correct

    In a small office/home office (SOHO) scenario where no RADIUS server is available and ease of setup is prioritized over highest security, WPA2-PSK would be the correct choice.

  • WEP with RADIUS

    Why it's wrong here

    WEP (Wired Equivalent Privacy) is an obsolete encryption protocol with severe cryptographic vulnerabilities, including a small Initialization Vector (IV) and weak key scheduling, making it easily crackable. Even when combined with a RADIUS server for authentication, WEP's fundamental encryption flaws expose all transmitted data to interception and decryption. This renders it completely unsuitable for any secure network, regardless of the authentication backend, and certainly not for deploying the highest security for employee devices.

    When this WOULD be correct

    If the question asked for a legacy authentication method that uses a RADIUS server for key distribution in a WEP-based network, then 'WEP with RADIUS' could be correct, though it would still be insecure.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

802.1X/EAPCorrect answer

Why this is correct

802.1X/EAP is the industry standard for enterprise wireless security, leveraging a RADIUS server for centralized authentication and authorization. This architecture enables robust per-user access control and dynamic key management, supporting various EAP methods like PEAP or EAP-TLS. It provides strong, individualized encryption keys and accountability, which is crucial for securing employee devices in a corporate environment demanding the highest security.

WPA3-SAEWrong answer — click to see why

Why this is wrong here

WPA3-SAE is a personal authentication mode that uses a shared password, not a RADIUS server. The question specifies using a RADIUS server for authentication, which requires an enterprise mode like 802.1X/EAP.

★ When this WOULD be the correct answer

If the question asked for the highest security standard for a small office/home office (SOHO) network without a RADIUS server, or for a network using only a pre-shared key, WPA3-SAE would be the correct answer.

Why candidates choose this

Candidates may know WPA3 is the latest Wi-Fi security standard and assume it is always the best choice, overlooking that SAE is a personal mode and does not integrate with RADIUS.

WPA2-PSKWrong answer — click to see why

Why this is wrong here

WPA2-PSK uses a pre-shared key for authentication, not a RADIUS server, so it does not meet the requirement for enterprise-grade authentication with a RADIUS server.

★ When this WOULD be the correct answer

In a small office/home office (SOHO) scenario where no RADIUS server is available and ease of setup is prioritized over highest security, WPA2-PSK would be the correct choice.

Why candidates choose this

Candidates may confuse WPA2-PSK with WPA2-Enterprise, or assume that PSK can be used with RADIUS, because both involve a password but the authentication mechanism differs.

WEP with RADIUSWrong answer — click to see why

Why this is wrong here

WEP with RADIUS is not a valid authentication method; WEP uses static keys or RADIUS for key distribution but is inherently insecure and does not meet 'highest security standard'.

★ When this WOULD be the correct answer

If the question asked for a legacy authentication method that uses a RADIUS server for key distribution in a WEP-based network, then 'WEP with RADIUS' could be correct, though it would still be insecure.

Why candidates choose this

Candidates may see 'RADIUS' and assume any combination with it is secure, overlooking that WEP is outdated and broken.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

Go deeper

Related to this question

About these practice questions

Courseiva writes every N10-009 question from scratch — 464 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.