ISC2 CC Network Security Practice Question
A financial services company wants to allow employees to use personal laptops on the corporate wireless network without installing company-managed certificates on those devices. The company still needs to authenticate each user and apply role-based access to internal applications. Which approach best meets these requirements?
⚠ Common exam trap
The trap here is treating the choice between EAP-TLS and PEAP-MSCHAPv2 as only a security-strength decision while overlooking the constraint that personal devices cannot receive corporate certificates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA2-Enterprise with PEAP-MSCHAPv2 using corporate directory credentials, plus a NAC or RADIUS authorization policy for role mapping.
PEAP-MSCHAPv2 authenticates users against the corporate directory using usernames and passwords, so no client certificate is needed on personal laptops. A RADIUS or NAC authorization policy then maps the authenticated identity to a role that governs access to internal applications. EAP-TLS requires certificates, WPA2-Personal has no per-user identity, and a captive portal lacks strong authentication and authorization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPA2-Personal with a strong pre-shared key and MAC address filtering for known laptops.
Why it's wrong here
A pre-shared key authenticates the network to the device but does not identify individual users, so role-based access cannot be applied per person. MAC address filtering is easily spoofed and does not scale. This option also shares one secret across all personal laptops, which weakens accountability and does not meet the user authentication requirement.
- ✗
An open wireless network with a captive portal that asks users to type their employee ID.
Why it's wrong here
An open network with a captive portal provides no cryptographic protection for the wireless traffic and only weak, easily spoofed identity checks. Typing an employee ID does not prove the user's identity or bind it to a directory account. It also cannot enforce role-based access to internal applications, so it fails both stated requirements.
- ✓
WPA2-Enterprise with PEAP-MSCHAPv2 using corporate directory credentials, plus a NAC or RADIUS authorization policy for role mapping.
Why this is correct
PEAP-MSCHAPv2 lets users authenticate with directory credentials without a client certificate on the personal laptop, satisfying the no-certificate constraint. The RADIUS or NAC layer can then apply authorization policies that map each user or group to a role, which controls access to internal applications. This combination meets both user authentication and role-based access.
- ✗
WPA2-Enterprise with EAP-TLS using a client certificate issued by the corporate PKI.
Why it's wrong here
EAP-TLS with a corporate client certificate provides strong mutual authentication, but it requires installing a certificate on each personal laptop. That conflicts with the requirement to avoid company-managed certificates on personal devices. It also does not by itself provide role-based access to internal applications; that needs an authorization layer after authentication.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Network Access Control
Network Access Control is a security solution that enforces policies to control which devices and users can connect to a network, ensuring only authorized and compliant endpoints gain access.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.