400-007 · Question #465
During initial preparations to deploy 802.1x for wired access to their network, a company must ensure that the solution complies with existing internal security policies. These policies mandate that…
The correct answer is A. PEAP. Protected EAP (PEAP) establishes a secure TLS tunnel authenticated with PKI certificates for both client and server. Inside this tunnel, user authentication is performed independently (commonly using EAP-MSCHAPv2), ensuring both compliance with PKI-based tunnel protection and…
Question
During initial preparations to deploy 802.1x for wired access to their network, a company must ensure that the solution complies with existing internal security policies. These policies mandate that every Auth-C/Auth-Z request must be protected by a tunnel which authenticates both server and clients using their PKI. At the same time, the user authentication phase must be independent of the tunnel. Which scheme meets the requirements?
Options
- APEAP
- BEAP-MSCHAPv2
- CEAP-MD5
- DEAP-FAST
How the community answered
(59 responses)- A73% (43)
- B15% (9)
- C3% (2)
- D8% (5)
Explanation
Protected EAP (PEAP) establishes a secure TLS tunnel authenticated with PKI certificates for both client and server. Inside this tunnel, user authentication is performed independently (commonly using EAP-MSCHAPv2), ensuring both compliance with PKI-based tunnel protection and separation of the inner authentication phase.
Topics
Community Discussion
No community discussion yet for this question.