Courseiva
Network Security →mediumMultiple Select

ISC2 CC Network Security Practice Question

A network administrator is hardening a corporate wireless network. Management wants to ensure that only authorized devices can associate and that wireless traffic cannot be easily read by someone nearby with a packet capture tool. Which two controls should the administrator implement? (Choose two.)

⚠ Common exam trap

The trap here is relying on obscurity controls like hidden SSIDs or spoofable MAC address lists instead of cryptographic authentication and encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA3 with strong authentication

Strong wireless encryption with robust authentication, such as WPA3, protects traffic from nearby eavesdropping, while 802.1X ensures only authenticated devices or users can associate. Together they address confidentiality and access control. WEP is broken, SSID hiding is easily defeated, and MAC filtering can be bypassed through spoofing, so none of those reliably satisfy the requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Media Access Control (MAC) address filtering

    Why it's wrong here

    MAC address filtering allows only listed hardware addresses, but addresses can be spoofed by an attacker, and managing lists does not scale well. It does not encrypt wireless traffic, so nearby eavesdropping remains possible. It fails to provide the strong authentication and confidentiality required by the scenario.

  • ✗

    Wired Equivalent Privacy (WEP)

    Why it's wrong here

    WEP is an obsolete wireless security protocol with well-known cryptographic weaknesses that allow keys to be recovered and traffic to be decrypted. It does not reliably prevent eavesdropping or unauthorized association. Deploying WEP would fail both the confidentiality and access-control requirements, so it is not an appropriate control.

  • ✓

    WPA3 with strong authentication

    Why this is correct

    WPA3 provides strong encryption for wireless traffic and supports authentication methods that verify authorized users or devices. This prevents casual eavesdropping by someone nearby and helps ensure only approved devices associate. It directly addresses both the confidentiality and access-control goals in the scenario.

  • ✗

    Service Set Identifier (SSID) broadcasting disabled

    Why it's wrong here

    Hiding the SSID does not prevent determined attackers from discovering the network name through probe requests and response frames. It also does not encrypt traffic or authenticate devices. Relying on SSID hiding provides a false sense of security and does not meet the stated confidentiality or access-control goals.

  • ✓

    IEEE 802.1X port-based network access control

    Why this is correct

    802.1X requires devices or users to authenticate through an authentication server before being granted network access. This enforces that only authorized devices can associate with the wireless network. Combined with strong encryption, it satisfies the requirement to restrict access to approved endpoints.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.