Courseiva
Network Security →easyMultiple Choice

ISC2 CC Network Security Practice Question

A small accounting firm's staff connect to the corporate wireless network using a shared passphrase that every employee knows, and the same passphrase has not been changed in two years. A security consultant recommends moving to a deployment where each user authenticates with their own domain credentials and a RADIUS server validates the logon before network access is granted. Which technology should the consultant recommend?

⚠ Common exam trap

The trap here is assuming that strengthening the pre-shared key or adding a portal page solves the shared-credential problem, when only per-user authentication through a RADIUS-backed 802.1X exchange actually does.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA2-Enterprise with 802.1X authentication

Enterprise-mode wireless security couples the 802.1X framework with a RADIUS server so each user presents unique credentials, commonly their domain logon, before access is granted. This eliminates the shared-secret weakness, enables per-user revocation, and produces authentication logs tied to individuals, which is exactly what the consultant was asked to deliver for the accounting firm.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A captive portal that displays an acceptable-use policy before granting access

    Why it's wrong here

    A captive portal presents a web page that users must accept before traffic is allowed, but it typically does not verify individual domain credentials against a RADIUS server and is easily bypassed by spoofing a MAC address. It addresses user awareness, not the authentication weakness of a shared passphrase, so it does not meet the scenario's need.

  • ✗

    WPA2-Personal with a longer and more complex pre-shared key

    Why it's wrong here

    WPA2-Personal still relies on a single pre-shared key shared by every client, so all staff would continue to use the same secret and no individual accountability exists. Lengthening the key improves resistance to brute force but does nothing to provide per-user domain credentials or RADIUS validation, so it fails the stated requirement.

  • ✗

    MAC address filtering on the wireless access points

    Why it's wrong here

    MAC address filtering permits or denies clients based on hardware addresses, which attackers can observe and clone trivially. It does not authenticate users, does not integrate with Active Directory or RADIUS, and does not remove the shared passphrase problem, so it is an inadequate control for this firm's requirement.

  • ✓

    WPA2-Enterprise with 802.1X authentication

    Why this is correct

    WPA2-Enterprise with 802.1X gives each user a unique credential validated by a RADIUS server before the client is granted network access, so a departing employee can be disabled individually. This directly replaces the shared passphrase model described in the scenario and satisfies the consultant's requirement for per-user domain authentication.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.