nerdexam
CompTIA

CAS-002 · Question #253

Three companies want to allow their employees to seamlessly connect to each other's wireless corporate networks while keeping one consistent wireless client configuration. Each company wants to…

The correct answer is A. The three companies should agree on a single SSID and configure a hierarchical RADIUS. Three companies need seamless wireless roaming with home-office authentication preserved, which is solved by a shared SSID and hierarchical RADIUS proxy that forwards authentication requests to each employee's home RADIUS server.

Technical Integration of Enterprise Components

Question

Three companies want to allow their employees to seamlessly connect to each other's wireless corporate networks while keeping one consistent wireless client configuration. Each company wants to maintain its own authentication infrastructure and wants to ensure that an employee who is visiting the other two companies is authenticated by the home office when connecting to the other companies' wireless network. All three companies have agreed to standardize on 802.1x EAP-PEAP-MSCHAPv2 for client configuration. Which of the following should the three companies implement?

Options

  • AThe three companies should agree on a single SSID and configure a hierarchical RADIUS
  • BThe three companies should implement federated authentication through Shibboleth
  • CThe three companies should implement a central portal-based single sign-on and agree to
  • DAll three companies should use the same wireless vendor to facilitate the use of a shared

How the community answered

(41 responses)
  • A
    51% (21)
  • B
    29% (12)
  • C
    7% (3)
  • D
    12% (5)

Why each option

Three companies need seamless wireless roaming with home-office authentication preserved, which is solved by a shared SSID and hierarchical RADIUS proxy that forwards authentication requests to each employee's home RADIUS server.

AThe three companies should agree on a single SSID and configure a hierarchical RADIUSCorrect

A shared SSID combined with hierarchical RADIUS (RADIUS proxy chaining) allows each company's access points to forward 802.1x EAP-PEAP-MSCHAPv2 authentication requests to the visiting employee's home RADIUS server. This preserves each company's independent authentication infrastructure while enabling a single, consistent wireless client configuration across all three networks.

BThe three companies should implement federated authentication through Shibboleth

Shibboleth is a federated identity solution designed for browser-based web SSO, not for 802.1x EAP-based wireless network authentication.

CThe three companies should implement a central portal-based single sign-on and agree to

A portal-based SSO requires browser interaction at a captive portal, which is incompatible with the agreed 802.1x EAP-PEAP-MSCHAPv2 client configuration that authenticates before network access.

DAll three companies should use the same wireless vendor to facilitate the use of a shared

Using the same wireless vendor is a procurement decision that does not address the requirement to route authentication requests back to each employee's home authentication infrastructure.

Concept tested: Hierarchical RADIUS proxy for 802.1x wireless federation

Source: https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-radius-proxy

Topics

#802.1x#RADIUS federation#EAP-PEAP#wireless authentication

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice