GSEC · Question #223
You work as a Network Administrator for McNeil Inc. The company has a Windows Server 2008 network environment. The network is configured as a Windows Active Directory-based single forest…
The correct answer is D. The wireless network communication will be secured. Two tasks were required: (1) secure wireless communication and (2) enable smart card authentication. Configuring 802.1x with WEP does secure the wireless link (Task 1 accomplished). However, PEAP-MS-CHAPv2 authenticates using username and password credentials - it does NOT…
Question
You work as a Network Administrator for McNeil Inc. The company has a Windows Server 2008 network environment. The network is configured as a Windows Active Directory-based single forest domain-based network. The company's management has decided to provide laptops to its sales team members. These laptops are equipped with smart card readers. The laptops will be configured as wireless network clients. You are required to accomplish the following tasks:
The wireless network communication should be secured. The laptop users should be able to use smart cards for getting authenticated. In order to accomplish the tasks, you take the following steps:
- Configure 802.1x and WEP for the wireless connections.
- Configure the PEAP-MS-CHAP v2 protocol for authentication.
What will happen after you have taken these steps?
Options
- AThe laptop users will be able to use smart cards for getting authenticated.
- BBoth tasks will be accomplished.
- CNone of the tasks will be accomplished.
- DThe wireless network communication will be secured.
How the community answered
(29 responses)- A7% (2)
- B14% (4)
- C3% (1)
- D76% (22)
Explanation
Two tasks were required: (1) secure wireless communication and (2) enable smart card authentication. Configuring 802.1x with WEP does secure the wireless link (Task 1 accomplished). However, PEAP-MS-CHAPv2 authenticates using username and password credentials - it does NOT support smart cards or certificates. To support smart card authentication, EAP-TLS would be required, as it uses certificate-based (PKI) authentication compatible with smart cards. Therefore, only the wireless security task is accomplished; smart card authentication remains unsupported with the chosen configuration.
Topics
Community Discussion
No community discussion yet for this question.