nerdexam
CompTIA

CAS-003 · Question #806

A company provides guest WiFi access to the internet and physically separates the guest network from the company's internal WIFI. Due to a recent incident in which an attacker gained access to the…

The correct answer is B. PKI certificates. WPA2 Enterprise with EAP-TLS (Extensible Authentication Protocol - Transport Layer Security) uses mutual certificate-based authentication. Unlike EAP-PEAP or EAP-TTLS which only require the server to present a certificate, EAP-TLS requires BOTH the authentication server AND…

Technical Integration of Enterprise Security

Question

A company provides guest WiFi access to the internet and physically separates the guest network from the company's internal WIFI. Due to a recent incident in which an attacker gained access to the compay's intend WIFI, the company plans to configure WPA2 Enterprise in an EAP- TLS configuration. Which of the following must be installed on authorized hosts for this new configuration to work properly?

Options

  • AActive Directory OPOs
  • BPKI certificates
  • CHost-based firewall
  • DNAC persistent agent

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    87% (20)
  • C
    9% (2)

Explanation

WPA2 Enterprise with EAP-TLS (Extensible Authentication Protocol - Transport Layer Security) uses mutual certificate-based authentication. Unlike EAP-PEAP or EAP-TTLS which only require the server to present a certificate, EAP-TLS requires BOTH the authentication server AND each authorized client device to present a valid digital certificate. These certificates must be issued by a trusted PKI (Public Key Infrastructure). Without a client-side PKI certificate installed on each authorized host, the device cannot complete the TLS handshake and will be denied access to the network. This is what makes EAP-TLS significantly more secure than password-based EAP methods - stolen credentials alone are insufficient without the corresponding certificate.

Topics

#WPA2 Enterprise#EAP-TLS#PKI certificates#wireless security

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice