SSCP Network and Communications Security Practice Question
During a wireless site survey, a security engineer identifies several security weaknesses. Which TWO measures should be implemented to improve wireless security for a corporate network using WPA2-Enterprise?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use 802.1X authentication with EAP-TLS and certificate-based authentication
Using 802.1X with EAP-TLS and disabling WPS are key improvements. WPA2-PSK is weaker than Enterprise, and MAC filtering is ineffective against determined attackers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use 802.1X authentication with EAP-TLS and certificate-based authentication
Why this is correct
EAP-TLS provides strong mutual authentication.
- ✗
Implement MAC address filtering to allow only known devices
Why it's wrong here
MAC addresses can be spoofed, providing weak security.
- ✗
Disable SSID broadcast to hide the network
Why it's wrong here
SSID hiding is a minor deterrent and easily bypassed.
- ✓
Ensure the RADIUS server uses a trusted certificate and validate client certificates
Why this is correct
Certificate validation prevents rogue AP and client impersonation.
- ✗
Enable WPS for easy client configuration
Why it's wrong here
WPS is vulnerable to brute-force attacks.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.