nerdexam
Cisco

200-301 · Question #1555

Refer to the exhibit. An engineer is creating a secure preshared key based SSID using WPA2 for a wireless network running on 2.4 GHz and 5 GHz. Which two tasks must the engineer perform to complete th

The correct answer is B. Select the AES (CCMP128) option for WPA2 WPA3 Encryption D. Select the PSK option for Auth Key Management. To configure a secure WPA2 preshared key (PSK) based SSID with AES encryption, the engineer must select PSK for Auth Key Management and AES (CCMP128) for encryption.

Submitted by fatima_kr· Mar 5, 2026Network Access

Question

Refer to the exhibit. An engineer is creating a secure preshared key based SSID using WPA2 for a wireless network running on 2.4 GHz and 5 GHz. Which two tasks must the engineer perform to complete the process? (Choose two.)

Exhibits

200-301 question #1555 exhibit 1
200-301 question #1555 exhibit 2

Options

  • ASelect the 802.1x option for Auth Key Management
  • BSelect the AES (CCMP128) option for WPA2 WPA3 Encryption
  • CSelect the AES option for Auth Key Management
  • DSelect the PSK option for Auth Key Management
  • ESelect the WPA Policy option.

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    82% (18)
  • C
    5% (1)
  • E
    9% (2)

Why each option

To configure a secure WPA2 preshared key (PSK) based SSID with AES encryption, the engineer must select PSK for Auth Key Management and AES (CCMP128) for encryption.

ASelect the 802.1x option for Auth Key Management

802.1x is an enterprise authentication framework that uses an authentication server (e.g., RADIUS) and is not used for PSK-based WPA2 networks.

BSelect the AES (CCMP128) option for WPA2 WPA3 EncryptionCorrect

AES (CCMP128) is the robust encryption standard required for WPA2, offering strong data confidentiality and integrity, and must be selected as the encryption method.

CSelect the AES option for Auth Key Management

AES is an encryption algorithm, not an Auth Key Management method; Auth Key Management defines how the key is established and managed (e.g., PSK or 802.1X).

DSelect the PSK option for Auth Key ManagementCorrect

For a preshared key (PSK) based SSID, 'PSK' must be selected under Auth Key Management to specify that authentication will occur via a shared secret rather than 802.1X.

ESelect the WPA Policy option.

Selecting 'WPA Policy' is a general step; the specific tasks involve selecting the WPA2 Policy and its associated encryption and authentication key management.

Concept tested: WPA2-PSK configuration with AES encryption

Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/wlan_security_wpa_wpa2.html

Topics

#Wireless security#WPA2-PSK#SSID configuration#AES encryption

Community Discussion

No community discussion yet for this question.

Full 200-301 Practice