mediumMultiple Choice
ISC2 CC Practice Question: A network administrator is configuring a wireless…
A network administrator is configuring a wireless network for a small office. Security requirements include strong encryption and pre-shared key authentication. Which protocol should be used?
⚠ Common exam trap
ISC2 often tests the distinction between PSK and Enterprise modes, where candidates mistakenly choose WPA3-Enterprise because it is newer, ignoring the explicit requirement for pre-shared key authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA2-PSK with AES
WPA2-PSK with AES is the correct choice because it provides strong encryption (AES-CCMP) and uses a pre-shared key for authentication, meeting the requirements for a small office without a RADIUS server. WPA2-PSK is widely supported and offers robust security against common attacks when a strong passphrase is used.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
WPA2-PSK with AES
Why this is correct
WPA2-PSK with AES satisfies both stated requirements: pre-shared key authentication and strong encryption through the AES-CCMP cipher. Older WEP and TKIP options are cryptographically broken, and enterprise modes require a RADIUS server rather than a pre-shared key.
- ✗
WPA3-Enterprise with 802.1X
Why it's wrong here
WPA3-Enterprise with 802.1X authenticates each user via a RADIUS server and per-session keys, not a shared pre-shared key as the stem requires. It is tempting because it is the strongest wireless option, and it is correct for large organisations needing individual accountability, but not for a small office specifying PSK.
- ✗
Open with MAC address filtering
Why it's wrong here
Open networks provide no encryption at all, and MAC address filtering is trivially spoofed, so neither strong encryption nor pre-shared key authentication is delivered. MAC filtering is tempting for low-risk guest or IoT segments needing casual access control, but it cannot satisfy cryptographic requirements.
- ✗
WEP with TKIP
Why it's wrong here
WEP with TKIP fails the strong-encryption requirement: WEP's RC4 keystream is cryptographically broken, and TKIP was a deprecated interim patch, not a modern cipher. It is tempting because WEP with TKIP is easy to configure on legacy hardware lacking WPA2/WPA3 support, where it would be the only available option.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
PSK
A pre-shared key (PSK) is a secret string of characters shared in advance between two parties to authenticate and encrypt wireless or VPN communications.
Key term
Pre-shared Key
A secret password or passphrase that two devices share beforehand to prove they are allowed to connect and communicate securely.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.