Courseiva
Network SecurityeasyMultiple ChoiceObjective-mapped

N10-009 Network Security Practice Question

A company wants to ensure that only devices with known MAC addresses can connect to the guest Wi-Fi network. Which security feature should be configured on the wireless controller?

⚠ Common exam trap

The N10-009 exam often tests the misconception that 802.1X or WPA2-Enterprise can filter by MAC address, but these are authentication protocols for user/device identity, not MAC-based access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

MAC filtering

MAC filtering allows the wireless controller to maintain an allowlist of known MAC addresses, so only devices with those addresses can associate with the guest SSID. This directly meets the requirement to restrict access based on MAC addresses without requiring authentication credentials from users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • WPA2-Enterprise

    Why it's wrong here

    WPA2-Enterprise is a robust wireless security mode designed for organizational networks, which integrates with an 802.1X authentication server, often RADIUS, to provide individual user or device authentication. This method requires each connecting entity to present unique credentials, such as a username and password, for validation, offering strong, scalable security. It focuses on identity-based authentication rather than simply filtering by a device's MAC address.

    When this WOULD be correct

    WPA2-Enterprise would be correct in a scenario where the company needs to authenticate individual users (e.g., using RADIUS with credentials or certificates) on a corporate Wi-Fi network, rather than restricting access by device MAC addresses.

  • MAC filtering

    Why this is correct

    MAC filtering is a network access control method that permits or denies network connectivity based on a device's unique Media Access Control (MAC) address. By maintaining an explicit whitelist of approved MAC addresses on a wireless access point or switch, only devices with known identifiers are granted access to the network. This directly addresses the requirement to ensure only devices with known MAC addresses can connect.

  • 802.1X

    Why it's wrong here

    802.1X is a port-based network access control protocol that authenticates users or devices before granting network access, typically using credentials like usernames and passwords or digital certificates. It leverages an authentication server, such as RADIUS, to validate identities rather than relying solely on a device's hardware MAC address. Therefore, it does not directly fulfill the requirement of restricting access based *only* on known MAC addresses.

    When this WOULD be correct

    A company wants to authenticate individual users connecting to the corporate WPA2-Enterprise network using their domain credentials. 802.1X with a RADIUS server would be the correct security feature to configure.

  • WPA3-Personal

    Why it's wrong here

    WPA3-Personal is a wireless security protocol primarily intended for home or small office networks, utilizing Simultaneous Authentication of Equals (SAE) to establish a secure connection with a pre-shared key. While it offers enhanced security over WPA2-Personal by mitigating dictionary attacks, its authentication mechanism relies on a shared secret, not on individual device MAC addresses. Consequently, it does not provide the specific functionality of allowing only devices with known MAC addresses.

    When this WOULD be correct

    WPA3-Personal would be the correct answer if the question asked for the most secure encryption method for a home or small office Wi-Fi network without a RADIUS server, or if the requirement was to protect against brute-force password attacks using Simultaneous Authentication of Equals (SAE).

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

MAC filteringCorrect answer

Why this is correct

MAC filtering is a network access control method that permits or denies network connectivity based on a device's unique Media Access Control (MAC) address. By maintaining an explicit whitelist of approved MAC addresses on a wireless access point or switch, only devices with known identifiers are granted access to the network. This directly addresses the requirement to ensure only devices with known MAC addresses can connect.

WPA2-EnterpriseWrong answer — click to see why

Why this is wrong here

WPA2-Enterprise provides authentication and encryption for wireless networks, but it does not restrict access based on MAC addresses. The question specifically asks for a feature that allows only devices with known MAC addresses to connect, which is MAC filtering, not an authentication protocol.

★ When this WOULD be the correct answer

WPA2-Enterprise would be correct in a scenario where the company needs to authenticate individual users (e.g., using RADIUS with credentials or certificates) on a corporate Wi-Fi network, rather than restricting access by device MAC addresses.

Why candidates choose this

Candidates may confuse MAC filtering with enterprise authentication methods, thinking that WPA2-Enterprise can control device access, but it actually focuses on user authentication and encryption, not MAC-based allowlisting.

802.1XWrong answer — click to see why

Why this is wrong here

802.1X is an authentication framework used with enterprise Wi-Fi (e.g., WPA2-Enterprise) to authenticate users via credentials, not devices by MAC address. It does not restrict access based on MAC addresses.

★ When this WOULD be the correct answer

A company wants to authenticate individual users connecting to the corporate WPA2-Enterprise network using their domain credentials. 802.1X with a RADIUS server would be the correct security feature to configure.

Why candidates choose this

Candidates may confuse 802.1X with MAC-based access control because both involve authentication, but 802.1X authenticates users, not device MAC addresses.

WPA3-PersonalWrong answer — click to see why

Why this is wrong here

WPA3-Personal is a wireless encryption standard that provides secure authentication and data encryption, but it does not restrict access based on device MAC addresses. The question specifically asks for a feature to allow only known MAC addresses, which is MAC filtering, not an encryption protocol.

★ When this WOULD be the correct answer

WPA3-Personal would be the correct answer if the question asked for the most secure encryption method for a home or small office Wi-Fi network without a RADIUS server, or if the requirement was to protect against brute-force password attacks using Simultaneous Authentication of Equals (SAE).

Why candidates choose this

Candidates may confuse security features, thinking that a stronger encryption protocol like WPA3 inherently includes access control mechanisms, or they may assume that newer standards automatically address all security concerns, including MAC-based restrictions.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 464 original N10-009 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.