nerdexam
Cisco

400-007 · Question #465

During initial preparations to deploy 802.1x for wired access to their network, a company must ensure that the solution complies with existing internal security policies. These policies mandate that…

The correct answer is A. PEAP. Protected EAP (PEAP) establishes a secure TLS tunnel authenticated with PKI certificates for both client and server. Inside this tunnel, user authentication is performed independently (commonly using EAP-MSCHAPv2), ensuring both compliance with PKI-based tunnel protection and…

Designing Security

Question

During initial preparations to deploy 802.1x for wired access to their network, a company must ensure that the solution complies with existing internal security policies. These policies mandate that every Auth-C/Auth-Z request must be protected by a tunnel which authenticates both server and clients using their PKI. At the same time, the user authentication phase must be independent of the tunnel. Which scheme meets the requirements?

Options

  • APEAP
  • BEAP-MSCHAPv2
  • CEAP-MD5
  • DEAP-FAST

How the community answered

(59 responses)
  • A
    73% (43)
  • B
    15% (9)
  • C
    3% (2)
  • D
    8% (5)

Explanation

Protected EAP (PEAP) establishes a secure TLS tunnel authenticated with PKI certificates for both client and server. Inside this tunnel, user authentication is performed independently (commonly using EAP-MSCHAPv2), ensuring both compliance with PKI-based tunnel protection and separation of the inner authentication phase.

Topics

#802.1x#PEAP#EAP methods#PKI tunnel authentication

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice