ISC2 CC Network Security Practice Question
A network administrator is hardening a corporate wireless network. Management wants to ensure that only authorized devices can associate and that wireless traffic cannot be easily read by someone nearby with a packet capture tool. Which two controls should the administrator implement? (Choose two.)
⚠ Common exam trap
The trap here is relying on obscurity controls like hidden SSIDs or spoofable MAC address lists instead of cryptographic authentication and encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA3 with strong authentication
Strong wireless encryption with robust authentication, such as WPA3, protects traffic from nearby eavesdropping, while 802.1X ensures only authenticated devices or users can associate. Together they address confidentiality and access control. WEP is broken, SSID hiding is easily defeated, and MAC filtering can be bypassed through spoofing, so none of those reliably satisfy the requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Media Access Control (MAC) address filtering
Why it's wrong here
MAC address filtering allows only listed hardware addresses, but addresses can be spoofed by an attacker, and managing lists does not scale well. It does not encrypt wireless traffic, so nearby eavesdropping remains possible. It fails to provide the strong authentication and confidentiality required by the scenario.
- ✗
Wired Equivalent Privacy (WEP)
Why it's wrong here
WEP is an obsolete wireless security protocol with well-known cryptographic weaknesses that allow keys to be recovered and traffic to be decrypted. It does not reliably prevent eavesdropping or unauthorized association. Deploying WEP would fail both the confidentiality and access-control requirements, so it is not an appropriate control.
- ✓
WPA3 with strong authentication
Why this is correct
WPA3 provides strong encryption for wireless traffic and supports authentication methods that verify authorized users or devices. This prevents casual eavesdropping by someone nearby and helps ensure only approved devices associate. It directly addresses both the confidentiality and access-control goals in the scenario.
- ✗
Service Set Identifier (SSID) broadcasting disabled
Why it's wrong here
Hiding the SSID does not prevent determined attackers from discovering the network name through probe requests and response frames. It also does not encrypt traffic or authenticate devices. Relying on SSID hiding provides a false sense of security and does not meet the stated confidentiality or access-control goals.
- ✓
IEEE 802.1X port-based network access control
Why this is correct
802.1X requires devices or users to authenticate through an authentication server before being granted network access. This enforces that only authorized devices can associate with the wireless network. Combined with strong encryption, it satisfies the requirement to restrict access to approved endpoints.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Security Foundations
Key term
MAC
MAC (Media Access Control) is a unique hardware identifier assigned to network interfaces for communication on a local network segment.
Key term
WPA3
WPA3 is the latest security standard for Wi-Fi networks, providing stronger encryption and protection against password guessing attacks compared to its predecessor WPA2.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.