SSCP Network and Communications Security Practice Question
During a wireless site survey, a security engineer identifies several security weaknesses. Which TWO measures should be implemented to improve wireless security for a corporate network using WPA2-Enterprise?
⚠ Common exam trap
SSCP often tests the misconception that hiding the SSID or using MAC filtering adds security, when in fact these are easily bypassed and not part of a robust WPA2-Enterprise implementation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use 802.1X authentication with EAP-TLS and certificate-based authentication
Option A is correct because WPA2-Enterprise relies on 802.1X for port-based network access control, and EAP-TLS with certificate-based authentication provides strong mutual authentication using digital certificates rather than weaker credential-based methods like PEAP-MSCHAPv2. Option D is correct because the RADIUS server must present a certificate from a trusted CA so supplicants can validate it and prevent rogue-AP/evil-twin attacks, while validating client certificates ensures only authorized devices/users complete the EAP-TLS exchange. Option B is not appropriate because MAC address filtering is trivially bypassed via spoofing and adds no real cryptographic protection. Option C is not appropriate because hiding the SSID is security through obscurity and the SSID is still discoverable in management frames. Option E is not appropriate because WPS is vulnerable to brute-force PIN attacks and should be disabled on corporate WPA2-Enterprise networks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use 802.1X authentication with EAP-TLS and certificate-based authentication
Why this is correct
802.1X with EAP-TLS satisfies WPA2-Enterprise's requirement for per-user authentication against a RADIUS server, using mutual certificate validation rather than shared credentials. This defeats rogue access points and credential-capture attacks, since the client verifies the server's certificate and each session derives unique encryption keys.
- ✗
Implement MAC address filtering to allow only known devices
Why it's wrong here
MAC filtering operates at layer 2 and only checks hardware identifiers, which attackers spoof trivially; it adds no cryptographic protection beyond WPA2-Enterprise's 802.1X authentication. It is tempting as a device allow-list for small, static networks, but it cannot stop credential theft or rogue access points here.
- ✗
Disable SSID broadcast to hide the network
Why it's wrong here
Hiding the SSID removes the beacon frame only; the network name still appears in probe responses and association frames, so it provides no cryptographic protection and breaks roaming. It is tempting for reducing casual discovery in home or guest networks, but WPA2-Enterprise weaknesses require stronger authentication, not obscurity.
- ✓
Ensure the RADIUS server uses a trusted certificate and validate client certificates
Why this is correct
Validating the RADIUS server's trusted certificate and checking client certificates prevents rogue-AP and evil-twin attacks during the EAP exchange. This satisfies the WPA2-Enterprise requirement by ensuring both ends of the 802.1X authentication are cryptographically verified.
- ✗
Enable WPS for easy client configuration
Why it's wrong here
WPS's PIN exchange is brute-forceable, so enabling it reintroduces the very weakness the survey flagged; WPA2-Enterprise already handles client onboarding via 802.1X/EAP. WPS suits home networks where push-button enrolment outweighs risk, not corporate deployments requiring certificate or credential authentication.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.