Courseiva
Question 134 of 747
easyMultiple ChoiceObjective-mapped

Which Wireless Protocol Provides the Strongest Authentication and Encryption?

A company wants to secure its wireless network. Which approach provides the strongest authentication and encryption?

Quick Answer

The answer is WPA2-Enterprise with RADIUS, as it provides the strongest wireless authentication and encryption for enterprise networks. This approach leverages 802.1X/EAP for per-user authentication against a central RADIUS server, combined with AES-CCMP encryption, which eliminates the shared passphrase vulnerability found in PSK modes and generates dynamic, unique session keys resistant to offline dictionary attacks and key reuse. On the CISSP exam, this question tests your understanding of the Wireless Security domain, often appearing as a trap where candidates mistakenly choose WPA3-Personal or WPA2-PSK due to familiarity with home networks; remember that enterprise-grade authentication always trumps pre-shared keys for strength. A useful memory tip: think of the acronym “RAD” for RADIUS, Authentication, and Dynamic keys—if you see RADIUS in the answer, it’s the strongest choice.

⚠ Common exam trap

It's easy for candidates to choose WPA2-PSK with a strong passphrase (Option D) because they think a long, complex passphrase is sufficient, but they overlook that PSK still lacks per-user authentication and is vulnerable to offline brute-force attacks once the 4-way handshake is captured.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

WPA2-Enterprise with RADIUS

WPA2-Enterprise with RADIUS provides the strongest authentication and encryption for wireless networks because it uses 802.1X/EAP for per-user authentication against a central RADIUS server, and AES-CCMP for encryption. This eliminates the shared passphrase vulnerability of PSK modes and supports dynamic, unique encryption keys per session, making it resistant to offline dictionary attacks and key reuse.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • WEP

    Why it's wrong here

    WEP is deprecated due to weak encryption.

  • Disabling SSID broadcast

    Why it's wrong here

    This obscures the network but does not provide authentication or encryption.

  • WPA2-Enterprise with RADIUS

    Why this is correct

    Provides per-user authentication and strong encryption.

  • WPA2-PSK with a strong passphrase

    Why it's wrong here

    Still uses a shared key, less secure than enterprise.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISSP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which two methods provide strong encryption and authentication for wireless networks? (Choose TWO.)

medium
  • A.WEP
  • B.WPA2-PSK
  • C.WPA2-Enterprise
  • D.MAC filtering
  • E.WPA3

Why C: WPA2-Enterprise (C) is correct because it uses IEEE 802.1X authentication with a RADIUS server, providing mutual authentication and per-session dynamic encryption keys via the 4-way handshake using AES-CCMP. WPA3 (E) is correct because it introduces Simultaneous Authentication of Equals (SAE) to replace the pre-shared key (PSK) handshake, offering forward secrecy and stronger encryption with GCMP-256, and also supports 802.1X for enterprise deployments.

Last reviewed: Jun 24, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.