ISC2 CC Network Security Practice Question
A small accounting firm's staff connect to the corporate wireless network using a shared passphrase that every employee knows, and the same passphrase has not been changed in two years. A security consultant recommends moving to a deployment where each user authenticates with their own domain credentials and a RADIUS server validates the logon before network access is granted. Which technology should the consultant recommend?
⚠ Common exam trap
The trap here is assuming that strengthening the pre-shared key or adding a portal page solves the shared-credential problem, when only per-user authentication through a RADIUS-backed 802.1X exchange actually does.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA2-Enterprise with 802.1X authentication
Enterprise-mode wireless security couples the 802.1X framework with a RADIUS server so each user presents unique credentials, commonly their domain logon, before access is granted. This eliminates the shared-secret weakness, enables per-user revocation, and produces authentication logs tied to individuals, which is exactly what the consultant was asked to deliver for the accounting firm.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A captive portal that displays an acceptable-use policy before granting access
Why it's wrong here
A captive portal presents a web page that users must accept before traffic is allowed, but it typically does not verify individual domain credentials against a RADIUS server and is easily bypassed by spoofing a MAC address. It addresses user awareness, not the authentication weakness of a shared passphrase, so it does not meet the scenario's need.
- ✗
WPA2-Personal with a longer and more complex pre-shared key
Why it's wrong here
WPA2-Personal still relies on a single pre-shared key shared by every client, so all staff would continue to use the same secret and no individual accountability exists. Lengthening the key improves resistance to brute force but does nothing to provide per-user domain credentials or RADIUS validation, so it fails the stated requirement.
- ✗
MAC address filtering on the wireless access points
Why it's wrong here
MAC address filtering permits or denies clients based on hardware addresses, which attackers can observe and clone trivially. It does not authenticate users, does not integrate with Active Directory or RADIUS, and does not remove the shared passphrase problem, so it is an inadequate control for this firm's requirement.
- ✓
WPA2-Enterprise with 802.1X authentication
Why this is correct
WPA2-Enterprise with 802.1X gives each user a unique credential validated by a RADIUS server before the client is granted network access, so a departing employee can be disabled individually. This directly replaces the shared passphrase model described in the scenario and satisfies the consultant's requirement for per-user domain authentication.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.