nerdexam
Cisco

200-301 · Question #666

Refer to the exhibit. What are the two steps an engineer must take to provide the highest encryption and authentication using domain credentials from LDAP?

The correct answer is B. Select WPA+WPA2 on Layer 2 Security E. Select 802.1X from under Authentication Key Management. To achieve the highest encryption and authentication using domain credentials via LDAP, an engineer must configure Layer 2 Security for WPA+WPA2 and enable 802.1X authentication.

Submitted by jakub_pl· Mar 5, 2026Network Access

Question

Refer to the exhibit. What are the two steps an engineer must take to provide the highest encryption and authentication using domain credentials from LDAP?

Exhibits

200-301 question #666 exhibit 1
200-301 question #666 exhibit 2

Options

  • ASelect PSK under Authentication Key Management
  • BSelect WPA+WPA2 on Layer 2 Security
  • CSelect Static-WEP + 802.1X on Layer 2 Security
  • DSelect WPA Policy with TKIP Encryption
  • ESelect 802.1X from under Authentication Key Management

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    84% (26)
  • C
    6% (2)
  • D
    3% (1)

Why each option

To achieve the highest encryption and authentication using domain credentials via LDAP, an engineer must configure Layer 2 Security for WPA+WPA2 and enable 802.1X authentication.

ASelect PSK under Authentication Key Management

PSK (Preshared Key) is suitable for home or small office networks but does not provide authentication using individual domain credentials from LDAP, which requires 802.1X.

BSelect WPA+WPA2 on Layer 2 SecurityCorrect

Selecting WPA+WPA2 on Layer 2 Security enables the use of both WPA and WPA2 protocols, with WPA2 offering the strongest encryption available (AES-CCMP) for current wireless standards, providing compatibility while ensuring the highest level for clients that support it.

CSelect Static-WEP + 802.1X on Layer 2 Security

Static-WEP is an outdated and insecure encryption method with known vulnerabilities, and using it with 802.1X would compromise the "highest encryption" requirement.

DSelect WPA Policy with TKIP Encryption

WPA Policy with TKIP Encryption, while better than WEP, is not considered the highest encryption; WPA2 with AES-CCMP is stronger.

ESelect 802.1X from under Authentication Key ManagementCorrect

Selecting 802.1X under Authentication Key Management allows the wireless system to integrate with an external authentication server, such as a RADIUS server, which can then use LDAP to validate user domain credentials, fulfilling the requirement for authentication using domain credentials.

Concept tested: Enterprise wireless security (802.1X, WPA2, AES)

Source: https://learn.microsoft.com/en-us/windows/win32/w8sdk/wlan-security-and-extensibility

Topics

#WPA2#802.1X#wireless encryption#LDAP authentication

Community Discussion

No community discussion yet for this question.

Full 200-301 Practice