Courseiva
Cryptography →mediumMultiple Choice

SSCP Cryptography Practice Question

A security administrator is configuring a new wireless network that must use a protocol providing strong encryption and mutual authentication. The organization requires that the solution support AES-CCMP and be based on the IEEE 802.11i standard. Which protocol should the administrator implement?

⚠ Common exam trap

The trap here is assuming that any WPA2 or WPA3 variant provides mutual authentication, when only enterprise modes with 802.1X do.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA2-Enterprise

WPA2-Enterprise is based on IEEE 802.11i and uses AES-CCMP for encryption. It supports mutual authentication through 802.1X and EAP, making it suitable for enterprise wireless networks. The other options either lack mutual authentication (WPA-Personal, WPA3-Personal) or are insecure and outdated (WEP).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPA-Personal

    Why it's wrong here

    WPA-Personal uses a pre-shared key (PSK) and does not provide mutual authentication between the client and an authentication server. It typically uses TKIP, which is weaker than AES-CCMP. While it can support AES in some implementations, it lacks the enterprise-grade mutual authentication required.

  • ✓

    WPA2-Enterprise

    Why this is correct

    WPA2-Enterprise implements the IEEE 802.11i standard and mandates AES-CCMP for encryption. It supports mutual authentication through 802.1X and EAP methods, allowing the client and server to authenticate each other. This meets the requirements for strong encryption and mutual authentication in a wireless network.

  • ✗

    WEP

    Why it's wrong here

    WEP is an outdated and insecure protocol that uses RC4 with static keys. It does not support AES-CCMP or mutual authentication and is easily cracked. It does not meet the IEEE 802.11i standard and should never be used for sensitive networks.

  • ✗

    WPA3-Personal

    Why it's wrong here

    WPA3-Personal uses Simultaneous Authentication of Equals (SAE) to provide forward secrecy and resistance to offline dictionary attacks, but it is designed for personal networks with a shared password. It does not provide mutual authentication via an authentication server, which is required for enterprise environments.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.