220-1102 · Question #207
A network administrator is deploying a client certificate to be used for Wi-Fi access for all devices in an organization. The certificate will be used in conjunction with the user's existing…
The correct answer is B. All Wi-Fi traffic will be encrypted in transit. NOTE: The marked correct answer (B - 'All Wi-Fi traffic will be encrypted in transit') appears questionable. Wi-Fi encryption (WPA2/WPA3) is handled at the protocol level, not by client certificates. The primary security benefit of deploying a client certificate in addition to…
Question
A network administrator is deploying a client certificate to be used for Wi-Fi access for all devices in an organization. The certificate will be used in conjunction with the user's existing username and password. Which of the following BEST describes the security benefits realized after this deployment?
Options
- AMultifactor authentication will be forced for Wi-Fi.
- BAll Wi-Fi traffic will be encrypted in transit.
- CEavesdropping attempts will be prevented.
- DRogue access points will not connect.
How the community answered
(27 responses)- A4% (1)
- B89% (24)
- C7% (2)
Explanation
NOTE: The marked correct answer (B - 'All Wi-Fi traffic will be encrypted in transit') appears questionable. Wi-Fi encryption (WPA2/WPA3) is handled at the protocol level, not by client certificates. The primary security benefit of deploying a client certificate in addition to a username and password is Multifactor Authentication (MFA) - the certificate is 'something you have' and the password is 'something you know,' satisfying two authentication factors. Answer A ('Multifactor authentication will be forced for Wi-Fi') is the more technically accurate answer for this scenario. Eavesdropping prevention (C) and blocking rogue APs (D) are not direct benefits of client certificates. If this appeared on a CompTIA A+ or Security+ exam, answer A better matches the described deployment. Accept A as the strongest answer based on the scenario description.
Topics
Community Discussion
No community discussion yet for this question.