Which TWO are common methods to secure a wireless network against unauthorized access?
Provides strong authentication per user.
Why this answer
WPA2-Enterprise (option A) is correct because it uses IEEE 802.1X authentication with a RADIUS server, requiring each user or device to authenticate with unique credentials or certificates, which prevents unauthorized clients from joining even if they know the pre-shared key. A wireless intrusion prevention system (option E) is correct because a WIPS continuously monitors the RF spectrum for rogue access points, evil twins, and deauthentication attacks, and can automatically contain or block those threats. Enabling SSID broadcast (option B) actually advertises the network and does not secure it, since hidden SSIDs are not a real security control anyway.
Disabling DHCP (option C) only forces manual IP configuration and is easily bypassed by an attacker who assigns a static address. MAC filtering (option D) is weak because MAC addresses can be spoofed, so it does not reliably prevent unauthorized access.
Exam trap
The trap here is that candidates often mistake MAC filtering or disabling DHCP as effective security controls, when in fact they are easily bypassed and provide only a false sense of security, while the exam expects recognition of enterprise-grade authentication and active monitoring as the correct methods.