CAS-003 · Question #806
A company provides guest WiFi access to the internet and physically separates the guest network from the company's internal WIFI. Due to a recent incident in which an attacker gained access to the…
The correct answer is B. PKI certificates. WPA2 Enterprise with EAP-TLS (Extensible Authentication Protocol - Transport Layer Security) uses mutual certificate-based authentication. Unlike EAP-PEAP or EAP-TTLS which only require the server to present a certificate, EAP-TLS requires BOTH the authentication server AND…
Question
A company provides guest WiFi access to the internet and physically separates the guest network from the company's internal WIFI. Due to a recent incident in which an attacker gained access to the compay's intend WIFI, the company plans to configure WPA2 Enterprise in an EAP- TLS configuration. Which of the following must be installed on authorized hosts for this new configuration to work properly?
Options
- AActive Directory OPOs
- BPKI certificates
- CHost-based firewall
- DNAC persistent agent
How the community answered
(23 responses)- A4% (1)
- B87% (20)
- C9% (2)
Explanation
WPA2 Enterprise with EAP-TLS (Extensible Authentication Protocol - Transport Layer Security) uses mutual certificate-based authentication. Unlike EAP-PEAP or EAP-TTLS which only require the server to present a certificate, EAP-TLS requires BOTH the authentication server AND each authorized client device to present a valid digital certificate. These certificates must be issued by a trusted PKI (Public Key Infrastructure). Without a client-side PKI certificate installed on each authorized host, the device cannot complete the TLS handshake and will be denied access to the network. This is what makes EAP-TLS significantly more secure than password-based EAP methods - stolen credentials alone are insufficient without the corresponding certificate.
Topics
Community Discussion
No community discussion yet for this question.