Courseiva
easyMultiple Select

SSCP Practice Question: Which TWO are common methods to secure a wireless…

Which TWO are common methods to secure a wireless network against unauthorized access?

⚠ Common exam trap

The trap here is that candidates often mistake MAC filtering or disabling DHCP as effective security controls, when in fact they are easily bypassed and provide only a false sense of security, while the exam expects recognition of enterprise-grade authentication and active monitoring as the correct methods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement WPA2-Enterprise

WPA2-Enterprise (option A) is correct because it uses IEEE 802.1X authentication with a RADIUS server, requiring each user or device to authenticate with unique credentials or certificates, which prevents unauthorized clients from joining even if they know the pre-shared key. A wireless intrusion prevention system (option E) is correct because a WIPS continuously monitors the RF spectrum for rogue access points, evil twins, and deauthentication attacks, and can automatically contain or block those threats. Enabling SSID broadcast (option B) actually advertises the network and does not secure it, since hidden SSIDs are not a real security control anyway. Disabling DHCP (option C) only forces manual IP configuration and is easily bypassed by an attacker who assigns a static address. MAC filtering (option D) is weak because MAC addresses can be spoofed, so it does not reliably prevent unauthorized access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement WPA2-Enterprise

    Why this is correct

    Provides strong authentication per user.

  • ✗

    Enable SSID broadcast

    Why it's wrong here

    Broadcasting helps clients find the network, not a security measure.

  • ✗

    Disable DHCP

    Why it's wrong here

    Disabling DHCP forces static IPs but does not prevent unauthorized clients.

  • ✗

    Use MAC filtering

    Why it's wrong here

    MAC addresses can be spoofed easily.

  • ✓

    Deploy a wireless intrusion prevention system (WIPS)

    Why this is correct

    A WIPS monitors the radio spectrum for rogue access points, evil-twin broadcasts and deauthentication floods, then blocks them automatically. This actively detects and mitigates unauthorised wireless access attempts, satisfying the stem's requirement for a common method of securing the network against intrusion.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.