Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: A network administrator is configuring a wireless…

A network administrator is configuring a wireless network for a small office. Security requirements include strong encryption and pre-shared key authentication. Which protocol should be used?

⚠ Common exam trap

ISC2 often tests the distinction between PSK and Enterprise modes, where candidates mistakenly choose WPA3-Enterprise because it is newer, ignoring the explicit requirement for pre-shared key authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA2-PSK with AES

WPA2-PSK with AES is the correct choice because it provides strong encryption (AES-CCMP) and uses a pre-shared key for authentication, meeting the requirements for a small office without a RADIUS server. WPA2-PSK is widely supported and offers robust security against common attacks when a strong passphrase is used.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    WPA2-PSK with AES

    Why this is correct

    WPA2-PSK with AES satisfies both stated requirements: pre-shared key authentication and strong encryption through the AES-CCMP cipher. Older WEP and TKIP options are cryptographically broken, and enterprise modes require a RADIUS server rather than a pre-shared key.

  • ✗

    WPA3-Enterprise with 802.1X

    Why it's wrong here

    WPA3-Enterprise with 802.1X authenticates each user via a RADIUS server and per-session keys, not a shared pre-shared key as the stem requires. It is tempting because it is the strongest wireless option, and it is correct for large organisations needing individual accountability, but not for a small office specifying PSK.

  • ✗

    Open with MAC address filtering

    Why it's wrong here

    Open networks provide no encryption at all, and MAC address filtering is trivially spoofed, so neither strong encryption nor pre-shared key authentication is delivered. MAC filtering is tempting for low-risk guest or IoT segments needing casual access control, but it cannot satisfy cryptographic requirements.

  • ✗

    WEP with TKIP

    Why it's wrong here

    WEP with TKIP fails the strong-encryption requirement: WEP's RC4 keystream is cryptographically broken, and TKIP was a deprecated interim patch, not a modern cipher. It is tempting because WEP with TKIP is easy to configure on legacy hardware lacking WPA2/WPA3 support, where it would be the only available option.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.