Courseiva

SSCP Network and Communications Security Practice Question

During a wireless site survey, a security engineer identifies several security weaknesses. Which TWO measures should be implemented to improve wireless security for a corporate network using WPA2-Enterprise?

⚠ Common exam trap

SSCP often tests the misconception that hiding the SSID or using MAC filtering adds security, when in fact these are easily bypassed and not part of a robust WPA2-Enterprise implementation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use 802.1X authentication with EAP-TLS and certificate-based authentication

Option A is correct because WPA2-Enterprise relies on 802.1X for port-based network access control, and EAP-TLS with certificate-based authentication provides strong mutual authentication using digital certificates rather than weaker credential-based methods like PEAP-MSCHAPv2. Option D is correct because the RADIUS server must present a certificate from a trusted CA so supplicants can validate it and prevent rogue-AP/evil-twin attacks, while validating client certificates ensures only authorized devices/users complete the EAP-TLS exchange. Option B is not appropriate because MAC address filtering is trivially bypassed via spoofing and adds no real cryptographic protection. Option C is not appropriate because hiding the SSID is security through obscurity and the SSID is still discoverable in management frames. Option E is not appropriate because WPS is vulnerable to brute-force PIN attacks and should be disabled on corporate WPA2-Enterprise networks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use 802.1X authentication with EAP-TLS and certificate-based authentication

    Why this is correct

    802.1X with EAP-TLS satisfies WPA2-Enterprise's requirement for per-user authentication against a RADIUS server, using mutual certificate validation rather than shared credentials. This defeats rogue access points and credential-capture attacks, since the client verifies the server's certificate and each session derives unique encryption keys.

  • ✗

    Implement MAC address filtering to allow only known devices

    Why it's wrong here

    MAC filtering operates at layer 2 and only checks hardware identifiers, which attackers spoof trivially; it adds no cryptographic protection beyond WPA2-Enterprise's 802.1X authentication. It is tempting as a device allow-list for small, static networks, but it cannot stop credential theft or rogue access points here.

  • ✗

    Disable SSID broadcast to hide the network

    Why it's wrong here

    Hiding the SSID removes the beacon frame only; the network name still appears in probe responses and association frames, so it provides no cryptographic protection and breaks roaming. It is tempting for reducing casual discovery in home or guest networks, but WPA2-Enterprise weaknesses require stronger authentication, not obscurity.

  • ✓

    Ensure the RADIUS server uses a trusted certificate and validate client certificates

    Why this is correct

    Validating the RADIUS server's trusted certificate and checking client certificates prevents rogue-AP and evil-twin attacks during the EAP exchange. This satisfies the WPA2-Enterprise requirement by ensuring both ends of the 802.1X authentication are cryptographically verified.

  • ✗

    Enable WPS for easy client configuration

    Why it's wrong here

    WPS's PIN exchange is brute-forceable, so enabling it reintroduces the very weakness the survey flagged; WPA2-Enterprise already handles client onboarding via 802.1X/EAP. WPS suits home networks where push-button enrolment outweighs risk, not corporate deployments requiring certificate or credential authentication.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.