N10-009 Network Implementation Practice Question
A company is deploying a new wireless network for employee devices and wants to use the most secure encryption method currently available for WPA2/3. Which encryption standard should be used?
⚠ Common exam trap
The N10-009 exam often tests the misconception that TKIP is acceptable for WPA2 security, but the trap is that WPA2 mandates AES-CCMP for certification, and TKIP is only a backward-compatible option that should never be used in a secure deployment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AES
AES (Advanced Encryption Standard) is the most secure encryption method available for WPA2 and WPA3. WPA2 mandates AES-CCMP, and WPA3 uses AES-GCMP, both of which are based on the AES block cipher, providing strong confidentiality and integrity. This makes AES the correct choice for the highest security in modern Wi-Fi deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WEP
Why it's wrong here
WEP (Wired Equivalent Privacy) was an early security protocol for 802.11 wireless networks, designed to provide confidentiality comparable to a wired LAN. However, it suffers from critical cryptographic vulnerabilities, including a weak initialization vector (IV) and poor key management, allowing attackers to easily recover the encryption key within minutes using readily available tools. Therefore, it is completely unsuitable for any new network deployment.
When this WOULD be correct
A question asking about legacy wireless security for older devices that only support WEP, or a scenario where maximum compatibility with very old hardware is required despite low security.
- ✗
TKIP
Why it's wrong here
TKIP (Temporal Key Integrity Protocol) was introduced with WPA as an interim solution to address WEP's vulnerabilities without requiring new hardware. It improved WEP by adding per-packet key mixing, a message integrity check, and a re-keying mechanism. However, TKIP still retains some underlying cryptographic weaknesses inherited from WEP and is susceptible to certain attacks, making it unsuitable for robust security and officially deprecated in WPA2 and WPA3.
When this WOULD be correct
TKIP would be correct in a question asking for backward compatibility with legacy devices that do not support AES, or in a scenario describing a mixed-mode WPA/WPA2 network where TKIP is used as a fallback for older clients.
- ✓
AES
Why this is correct
AES (Advanced Encryption Standard) is the current industry standard for strong symmetric-key encryption, adopted by the U.S. government and widely used globally. It provides robust confidentiality and integrity for wireless networks, forming the cryptographic backbone of modern Wi-Fi security protocols like WPA2 and WPA3. Its strength against known attacks makes it the recommended choice for securing sensitive employee data in new deployments.
- ✗
DES
Why it's wrong here
DES (Data Encryption Standard) is a symmetric-key block cipher developed in the 1970s, primarily for general data encryption, not specifically wireless. Its 56-bit key size is now considered far too short to withstand brute-force attacks from modern computing power, rendering it cryptographically insecure. While historically significant, DES was never integrated into Wi-Fi security standards and has been superseded by stronger algorithms like AES for all practical purposes.
When this WOULD be correct
DES would be correct if the question asked about legacy encryption standards for securing data at rest, such as in a scenario involving older systems that require DES for compatibility with legacy hardware or software.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓AESCorrect answer▾
Why this is correct
AES (Advanced Encryption Standard) is the current industry standard for strong symmetric-key encryption, adopted by the U.S. government and widely used globally. It provides robust confidentiality and integrity for wireless networks, forming the cryptographic backbone of modern Wi-Fi security protocols like WPA2 and WPA3. Its strength against known attacks makes it the recommended choice for securing sensitive employee data in new deployments.
✗WEPWrong answer — click to see why▾
Why this is wrong here
WEP is an outdated encryption standard with known vulnerabilities, easily cracked, and is not considered secure for modern WPA2/3 networks.
★ When this WOULD be the correct answer
A question asking about legacy wireless security for older devices that only support WEP, or a scenario where maximum compatibility with very old hardware is required despite low security.
Why candidates choose this
Candidates may confuse WEP with WPA or think it is still acceptable because it was once the standard, or they may misremember the acronym as a valid encryption method.
✗TKIPWrong answer — click to see why▾
Why this is wrong here
TKIP is an older encryption protocol used with WPA, but it is not considered secure for WPA2/3. WPA2 and WPA3 require AES (CCMP) for strong encryption; TKIP is deprecated due to vulnerabilities.
★ When this WOULD be the correct answer
TKIP would be correct in a question asking for backward compatibility with legacy devices that do not support AES, or in a scenario describing a mixed-mode WPA/WPA2 network where TKIP is used as a fallback for older clients.
Why candidates choose this
Candidates may confuse TKIP as a secure option because it was part of the original WPA standard and is still supported in some configurations, but they overlook that AES is mandatory for WPA2/3 security.
✗DESWrong answer — click to see why▾
Why this is wrong here
DES is an outdated symmetric encryption algorithm used primarily for data at rest, not for wireless network encryption. WPA2/3 uses AES (Advanced Encryption Standard) as the most secure encryption method, not DES.
★ When this WOULD be the correct answer
DES would be correct if the question asked about legacy encryption standards for securing data at rest, such as in a scenario involving older systems that require DES for compatibility with legacy hardware or software.
Why candidates choose this
Candidates may confuse DES with AES due to similar acronyms or mistakenly think DES is a wireless encryption standard because it is a well-known encryption algorithm, even though it is not used in Wi-Fi security.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Wireless Standards and Configuration
Key term
Wi-Fi
Wi-Fi is a technology that lets devices like laptops and phones connect to the internet or communicate with each other wirelessly using radio waves.
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
About these practice questions
Courseiva writes every N10-009 question from scratch — 464 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.