Question 134 of 747
easyMultiple ChoiceObjective-mapped
Which Wireless Protocol Provides the Strongest Authentication and Encryption?
A company wants to secure its wireless network. Which approach provides the strongest authentication and encryption?
Quick Answer
The answer is WPA2-Enterprise with RADIUS, as it provides the strongest wireless authentication and encryption for enterprise networks. This approach leverages 802.1X/EAP for per-user authentication against a central RADIUS server, combined with AES-CCMP encryption, which eliminates the shared passphrase vulnerability found in PSK modes and generates dynamic, unique session keys resistant to offline dictionary attacks and key reuse. On the CISSP exam, this question tests your understanding of the Wireless Security domain, often appearing as a trap where candidates mistakenly choose WPA3-Personal or WPA2-PSK due to familiarity with home networks; remember that enterprise-grade authentication always trumps pre-shared keys for strength. A useful memory tip: think of the acronym “RAD” for RADIUS, Authentication, and Dynamic keys—if you see RADIUS in the answer, it’s the strongest choice.
⚠ Common exam trap
It's easy for candidates to choose WPA2-PSK with a strong passphrase (Option D) because they think a long, complex passphrase is sufficient, but they overlook that PSK still lacks per-user authentication and is vulnerable to offline brute-force attacks once the 4-way handshake is captured.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA2-Enterprise with RADIUS
WPA2-Enterprise with RADIUS provides the strongest authentication and encryption for wireless networks because it uses 802.1X/EAP for per-user authentication against a central RADIUS server, and AES-CCMP for encryption. This eliminates the shared passphrase vulnerability of PSK modes and supports dynamic, unique encryption keys per session, making it resistant to offline dictionary attacks and key reuse.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WEP
Why it's wrong here
WEP is deprecated due to weak encryption.
- ✗
Disabling SSID broadcast
Why it's wrong here
This obscures the network but does not provide authentication or encryption.
- ✓
WPA2-Enterprise with RADIUS
Why this is correct
Provides per-user authentication and strong encryption.
- ✗
WPA2-PSK with a strong passphrase
Why it's wrong here
Still uses a shared key, less secure than enterprise.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISSP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which two methods provide strong encryption and authentication for wireless networks? (Choose TWO.)
medium- A.WEP
- B.WPA2-PSK
- ✓ C.WPA2-Enterprise
- D.MAC filtering
- ✓ E.WPA3
Why C: WPA2-Enterprise (C) is correct because it uses IEEE 802.1X authentication with a RADIUS server, providing mutual authentication and per-session dynamic encryption keys via the 4-way handshake using AES-CCMP. WPA3 (E) is correct because it introduces Simultaneous Authentication of Equals (SAE) to replace the pre-shared key (PSK) handshake, offering forward secrecy and stronger encryption with GCMP-256, and also supports 802.1X for enterprise deployments.
Last reviewed: Jun 24, 2026
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.