nerdexam
CompTIA

CAS-003 · Question #572

A new security policy states all wireless and wired authentication must include the use of certificates when connecting to internal resources within the enterprise LAN by all employees. Which of the…

The correct answer is C. 802.1X F. PKI. Certificate-based authentication for both wired and wireless connections requires two complementary components. 802.1X (C) is the IEEE standard for port-based Network Access Control (NAC) that enforces authentication before granting LAN/WLAN access; it supports EAP-TLS, which…

Technical Integration of Enterprise Security

Question

A new security policy states all wireless and wired authentication must include the use of certificates when connecting to internal resources within the enterprise LAN by all employees. Which of the following should be configured to comply with the new security policy? (Choose two.)

Options

  • ASSO
  • BNew pre-shared key
  • C802.1X
  • DOAuth
  • EPush-based authentication
  • FPKI

How the community answered

(51 responses)
  • B
    2% (1)
  • C
    88% (45)
  • D
    6% (3)
  • E
    4% (2)

Explanation

Certificate-based authentication for both wired and wireless connections requires two complementary components. 802.1X (C) is the IEEE standard for port-based Network Access Control (NAC) that enforces authentication before granting LAN/WLAN access; it supports EAP-TLS, which uses certificates instead of passwords, for both wired switches and wireless access points (WPA2/3-Enterprise). PKI (F) is the underlying infrastructure required to issue, distribute, manage, and validate the digital certificates used in 802.1X/EAP-TLS - without a PKI, there are no certificates to use. Option A (SSO) is for federated identity across applications, not network port authentication. Option B (pre-shared keys) is the opposite of certificate-based. Option D (OAuth) is an authorization delegation framework for APIs and web apps. Option E (push-based authentication) uses mobile app approvals, not certificates.

Topics

#802.1X#PKI#certificate-based authentication#network access control

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice