easyMultiple Select
SSCP Practice Question: Which TWO are common methods to secure a wireless…
Which TWO are common methods to secure a wireless network against unauthorized access?
⚠ Common exam trap
The trap here is that candidates often mistake MAC filtering or disabling DHCP as effective security controls, when in fact they are easily bypassed and provide only a false sense of security, while the exam expects recognition of enterprise-grade authentication and active monitoring as the correct methods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement WPA2-Enterprise
WPA2-Enterprise (option A) is correct because it uses IEEE 802.1X authentication with a RADIUS server, requiring each user or device to authenticate with unique credentials or certificates, which prevents unauthorized clients from joining even if they know the pre-shared key. A wireless intrusion prevention system (option E) is correct because a WIPS continuously monitors the RF spectrum for rogue access points, evil twins, and deauthentication attacks, and can automatically contain or block those threats. Enabling SSID broadcast (option B) actually advertises the network and does not secure it, since hidden SSIDs are not a real security control anyway. Disabling DHCP (option C) only forces manual IP configuration and is easily bypassed by an attacker who assigns a static address. MAC filtering (option D) is weak because MAC addresses can be spoofed, so it does not reliably prevent unauthorized access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement WPA2-Enterprise
Why this is correct
Provides strong authentication per user.
- ✗
Enable SSID broadcast
Why it's wrong here
Broadcasting helps clients find the network, not a security measure.
- ✗
Disable DHCP
Why it's wrong here
Disabling DHCP forces static IPs but does not prevent unauthorized clients.
- ✗
Use MAC filtering
Why it's wrong here
MAC addresses can be spoofed easily.
- ✓
Deploy a wireless intrusion prevention system (WIPS)
Why this is correct
A WIPS monitors the radio spectrum for rogue access points, evil-twin broadcasts and deauthentication floods, then blocks them automatically. This actively detects and mitigates unauthorised wireless access attempts, satisfying the stem's requirement for a common method of securing the network against intrusion.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.