SSCP Network and Communications Security Practice Question
A security analyst is hardening a wireless network that uses WPA2-Enterprise with a RADIUS server. The analyst wants to mitigate the risk of an attacker setting up a rogue access point to capture user credentials. Which TWO measures should be implemented? (Choose two.)
⚠ Common exam trap
The trap here is assuming that hiding the SSID or using PMF is sufficient to prevent rogue access points, when in fact mutual authentication and active monitoring are required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a Wireless Intrusion Prevention System (WIPS) to detect and contain rogue access points.
Deploying a WIPS detects and contains rogue access points, directly addressing the threat. Configuring 802.1X with EAP-TLS ensures mutual authentication, so clients verify the server's certificate and will not connect to a rogue AP. Together, these measures prevent credential harvesting. PMF, hidden SSIDs, and PSKs do not adequately mitigate the risk of a rogue AP capturing credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy a Wireless Intrusion Prevention System (WIPS) to detect and contain rogue access points.
Why this is correct
A WIPS monitors the wireless spectrum for unauthorized access points and can automatically contain them by sending deauthentication frames or alerting administrators. This directly mitigates the risk of a rogue AP capturing credentials by identifying and blocking it. It is a proactive measure that addresses the specific threat of rogue access points in the environment.
- ✗
Enable Protected Management Frames (PMF) to prevent deauthentication attacks.
Why it's wrong here
PMF protects against forging deauthentication and disassociation frames, which are used in denial-of-service and some evil twin attacks. However, it does not directly prevent an attacker from setting up a rogue access point to capture credentials. While PMF is a good security measure, it does not address the specific risk of credential harvesting via a rogue AP.
- ✗
Use a preshared key (PSK) instead of 802.1X to simplify authentication.
Why it's wrong here
Using a PSK instead of 802.1X would weaken security. PSKs are shared secrets that can be compromised and do not provide per-user authentication or mutual authentication. An attacker could set up a rogue AP with the same PSK and capture traffic, or the PSK could be leaked. This does not mitigate the risk and is contrary to the requirement for WPA2-Enterprise.
- ✓
Configure 802.1X authentication with EAP-TLS, requiring client certificates.
Why this is correct
EAP-TLS uses mutual authentication with certificates on both the client and server. This prevents an attacker from impersonating a legitimate access point because the client verifies the server's certificate. Even if a user connects to a rogue AP, the rogue AP cannot present a valid certificate, so the client will not send credentials. This effectively mitigates credential harvesting.
- ✗
Disable SSID broadcasting to hide the network name.
Why it's wrong here
Disabling SSID broadcasting does not provide security; it only makes the network slightly less visible. Attackers can easily discover hidden SSIDs using wireless analyzers. It does not prevent a rogue access point from being set up or from capturing credentials. Therefore, it is not a valid mitigation for the stated risk.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.