Courseiva
Network ImplementationmediumMultiple ChoiceObjective-mapped

N10-009 Network Implementation Practice Question

A company is deploying a new wireless network for employee devices and wants to use the most secure encryption method currently available for WPA2/3. Which encryption standard should be used?

⚠ Common exam trap

The N10-009 exam often tests the misconception that TKIP is acceptable for WPA2 security, but the trap is that WPA2 mandates AES-CCMP for certification, and TKIP is only a backward-compatible option that should never be used in a secure deployment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AES

AES (Advanced Encryption Standard) is the most secure encryption method available for WPA2 and WPA3. WPA2 mandates AES-CCMP, and WPA3 uses AES-GCMP, both of which are based on the AES block cipher, providing strong confidentiality and integrity. This makes AES the correct choice for the highest security in modern Wi-Fi deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • WEP

    Why it's wrong here

    WEP (Wired Equivalent Privacy) was an early security protocol for 802.11 wireless networks, designed to provide confidentiality comparable to a wired LAN. However, it suffers from critical cryptographic vulnerabilities, including a weak initialization vector (IV) and poor key management, allowing attackers to easily recover the encryption key within minutes using readily available tools. Therefore, it is completely unsuitable for any new network deployment.

    When this WOULD be correct

    A question asking about legacy wireless security for older devices that only support WEP, or a scenario where maximum compatibility with very old hardware is required despite low security.

  • TKIP

    Why it's wrong here

    TKIP (Temporal Key Integrity Protocol) was introduced with WPA as an interim solution to address WEP's vulnerabilities without requiring new hardware. It improved WEP by adding per-packet key mixing, a message integrity check, and a re-keying mechanism. However, TKIP still retains some underlying cryptographic weaknesses inherited from WEP and is susceptible to certain attacks, making it unsuitable for robust security and officially deprecated in WPA2 and WPA3.

    When this WOULD be correct

    TKIP would be correct in a question asking for backward compatibility with legacy devices that do not support AES, or in a scenario describing a mixed-mode WPA/WPA2 network where TKIP is used as a fallback for older clients.

  • AES

    Why this is correct

    AES (Advanced Encryption Standard) is the current industry standard for strong symmetric-key encryption, adopted by the U.S. government and widely used globally. It provides robust confidentiality and integrity for wireless networks, forming the cryptographic backbone of modern Wi-Fi security protocols like WPA2 and WPA3. Its strength against known attacks makes it the recommended choice for securing sensitive employee data in new deployments.

  • DES

    Why it's wrong here

    DES (Data Encryption Standard) is a symmetric-key block cipher developed in the 1970s, primarily for general data encryption, not specifically wireless. Its 56-bit key size is now considered far too short to withstand brute-force attacks from modern computing power, rendering it cryptographically insecure. While historically significant, DES was never integrated into Wi-Fi security standards and has been superseded by stronger algorithms like AES for all practical purposes.

    When this WOULD be correct

    DES would be correct if the question asked about legacy encryption standards for securing data at rest, such as in a scenario involving older systems that require DES for compatibility with legacy hardware or software.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

AESCorrect answer

Why this is correct

AES (Advanced Encryption Standard) is the current industry standard for strong symmetric-key encryption, adopted by the U.S. government and widely used globally. It provides robust confidentiality and integrity for wireless networks, forming the cryptographic backbone of modern Wi-Fi security protocols like WPA2 and WPA3. Its strength against known attacks makes it the recommended choice for securing sensitive employee data in new deployments.

WEPWrong answer — click to see why

Why this is wrong here

WEP is an outdated encryption standard with known vulnerabilities, easily cracked, and is not considered secure for modern WPA2/3 networks.

★ When this WOULD be the correct answer

A question asking about legacy wireless security for older devices that only support WEP, or a scenario where maximum compatibility with very old hardware is required despite low security.

Why candidates choose this

Candidates may confuse WEP with WPA or think it is still acceptable because it was once the standard, or they may misremember the acronym as a valid encryption method.

TKIPWrong answer — click to see why

Why this is wrong here

TKIP is an older encryption protocol used with WPA, but it is not considered secure for WPA2/3. WPA2 and WPA3 require AES (CCMP) for strong encryption; TKIP is deprecated due to vulnerabilities.

★ When this WOULD be the correct answer

TKIP would be correct in a question asking for backward compatibility with legacy devices that do not support AES, or in a scenario describing a mixed-mode WPA/WPA2 network where TKIP is used as a fallback for older clients.

Why candidates choose this

Candidates may confuse TKIP as a secure option because it was part of the original WPA standard and is still supported in some configurations, but they overlook that AES is mandatory for WPA2/3 security.

DESWrong answer — click to see why

Why this is wrong here

DES is an outdated symmetric encryption algorithm used primarily for data at rest, not for wireless network encryption. WPA2/3 uses AES (Advanced Encryption Standard) as the most secure encryption method, not DES.

★ When this WOULD be the correct answer

DES would be correct if the question asked about legacy encryption standards for securing data at rest, such as in a scenario involving older systems that require DES for compatibility with legacy hardware or software.

Why candidates choose this

Candidates may confuse DES with AES due to similar acronyms or mistakenly think DES is a wireless encryption standard because it is a well-known encryption algorithm, even though it is not used in Wi-Fi security.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every N10-009 question from scratch — 464 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.