LFCS Networking Practice Question
A Linux server running NetworkManager has a Wi-Fi interface wlp3s0 that must connect to the corporate WPA2-Enterprise network 'CorpNet' with 802.1X PEAP authentication, using identity 'jdoe' and password 'S3cr3t!'. The administrator wants to create and activate this connection entirely from the command line without editing configuration files manually. Which sequence of commands will accomplish this?
⚠ Common exam trap
The trap here is assuming that a simple 'nmcli dev wifi connect' with a password is sufficient for any secured Wi-Fi network, when enterprise networks require explicit 802.1X/EAP parameters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
nmcli con add type wifi ifname wlp3s0 con-name CorpNet ssid CorpNet, then nmcli con modify CorpNet wifi-sec.key-mgmt wpa-eap 802-1x.eap peap 802-1x.identity jdoe 802-1x.password 'S3cr3t!', then nmcli con up CorpNet
The correct approach uses 'nmcli con add type wifi' to create a profile, then 'nmcli con modify' to set 'wifi-sec.key-mgmt wpa-eap' and the 802.1X parameters (EAP method, identity, password), and finally 'nmcli con up' to activate it. WPA2-Enterprise requires 802.1X/EAP configuration, not a pre-shared key, and the connection type must match the wireless interface for NetworkManager to manage it properly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
nmcli con add type ethernet ifname wlp3s0 con-name CorpNet, then nmcli con up CorpNet
Why it's wrong here
This command creates an Ethernet-type connection bound to a wireless interface, which is incorrect. NetworkManager distinguishes between Wi-Fi and Ethernet connection types; using 'type ethernet' for a Wi-Fi device will not enable wireless scanning or association, and no SSID or security settings are defined. The connection will not bring up the wireless link to CorpNet.
- ✗
nmcli con add type wifi ifname wlp3s0 con-name CorpNet ssid CorpNet wifi-sec.key-mgmt wpa-psk wifi-sec.psk 'S3cr3t!'
Why it's wrong here
This creates a Wi-Fi profile using WPA-PSK with a pre-shared key, which is the wrong security mode for a WPA2-Enterprise network. The corporate network expects 802.1X/EAP authentication, not a shared passphrase. Even though the interface and SSID are correct, the connection will be rejected because the key management and authentication method do not match the RADIUS configuration.
- ✓
nmcli con add type wifi ifname wlp3s0 con-name CorpNet ssid CorpNet, then nmcli con modify CorpNet wifi-sec.key-mgmt wpa-eap 802-1x.eap peap 802-1x.identity jdoe 802-1x.password 'S3cr3t!', then nmcli con up CorpNet
Why this is correct
This is the correct sequence: 'nmcli con add type wifi' creates the profile with the given ssid and interface, 'nmcli con modify' sets the key management to wpa-eap and the 802.1X parameters including eap method, identity, and password, and 'nmcli con up' activates it. All required fields for WPA2-Enterprise are supplied, so the connection will authenticate and associate without manual file editing.
- ✗
nmcli dev wifi connect CorpNet password 'S3cr3t!'
Why it's wrong here
The 'nmcli dev wifi connect' command with a simple password creates a WPA-PSK (personal) connection, not WPA2-Enterprise. It cannot supply the 802.1X identity or EAP method required by PEAP, so authentication against the corporate RADIUS server will fail. This command is useful for home or small-office Wi-Fi, but it does not handle enterprise authentication parameters.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every LFCS question from scratch — 406 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.