Courseiva
Network Security →hardMultiple Choice

ISC2 CC Network Security Practice Question

A financial services company wants to allow employees to use personal laptops on the corporate wireless network without installing company-managed certificates on those devices. The company still needs to authenticate each user and apply role-based access to internal applications. Which approach best meets these requirements?

⚠ Common exam trap

The trap here is treating the choice between EAP-TLS and PEAP-MSCHAPv2 as only a security-strength decision while overlooking the constraint that personal devices cannot receive corporate certificates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA2-Enterprise with PEAP-MSCHAPv2 using corporate directory credentials, plus a NAC or RADIUS authorization policy for role mapping.

PEAP-MSCHAPv2 authenticates users against the corporate directory using usernames and passwords, so no client certificate is needed on personal laptops. A RADIUS or NAC authorization policy then maps the authenticated identity to a role that governs access to internal applications. EAP-TLS requires certificates, WPA2-Personal has no per-user identity, and a captive portal lacks strong authentication and authorization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPA2-Personal with a strong pre-shared key and MAC address filtering for known laptops.

    Why it's wrong here

    A pre-shared key authenticates the network to the device but does not identify individual users, so role-based access cannot be applied per person. MAC address filtering is easily spoofed and does not scale. This option also shares one secret across all personal laptops, which weakens accountability and does not meet the user authentication requirement.

  • ✗

    An open wireless network with a captive portal that asks users to type their employee ID.

    Why it's wrong here

    An open network with a captive portal provides no cryptographic protection for the wireless traffic and only weak, easily spoofed identity checks. Typing an employee ID does not prove the user's identity or bind it to a directory account. It also cannot enforce role-based access to internal applications, so it fails both stated requirements.

  • ✓

    WPA2-Enterprise with PEAP-MSCHAPv2 using corporate directory credentials, plus a NAC or RADIUS authorization policy for role mapping.

    Why this is correct

    PEAP-MSCHAPv2 lets users authenticate with directory credentials without a client certificate on the personal laptop, satisfying the no-certificate constraint. The RADIUS or NAC layer can then apply authorization policies that map each user or group to a role, which controls access to internal applications. This combination meets both user authentication and role-based access.

  • ✗

    WPA2-Enterprise with EAP-TLS using a client certificate issued by the corporate PKI.

    Why it's wrong here

    EAP-TLS with a corporate client certificate provides strong mutual authentication, but it requires installing a certificate on each personal laptop. That conflicts with the requirement to avoid company-managed certificates on personal devices. It also does not by itself provide role-based access to internal applications; that needs an authorization layer after authentication.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

Go deeper

Related to this question

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.