H12-323_V2.0 · Question #118
A government needs to deploy a WLAN network. The link authentication uses open system authentication, but the security requirements are extremely high. When engineers select security strategies…
The correct answer is A. WPA3-802.IX. WPA3-Enterprise (802.1X) is correct because it provides the highest level of WLAN security available - combining WPA3's strong encryption (including 192-bit cryptographic strength in government/enterprise mode) with 802.1X's per-user authentication via a RADIUS server, making…
Question
A government needs to deploy a WLAN network. The link authentication uses open system authentication, but the security requirements are extremely high. When engineers select security strategies, which of the following should they use first?
Options
- AWPA3-802.IX
- BStatic WEP
- CWPA/WPA2-PPSK
- DOWE
How the community answered
(53 responses)- A79% (42)
- B6% (3)
- C4% (2)
- D11% (6)
Explanation
WPA3-Enterprise (802.1X) is correct because it provides the highest level of WLAN security available - combining WPA3's strong encryption (including 192-bit cryptographic strength in government/enterprise mode) with 802.1X's per-user authentication via a RADIUS server, making it ideal for high-security government deployments. Open system authentication operates at the link layer and is perfectly compatible with WPA3-802.1X, which handles security at a higher layer.
OWE (D) is wrong because it only adds opportunistic encryption to open networks - it prevents passive eavesdropping but provides no authentication, making it suitable for public hotspots, not secure government networks. WPA/WPA2-PPSK (C) is weaker because it still relies on pre-shared key mechanics (even with per-user keys), which lacks the centralized, certificate-based authentication that enterprise security demands. Static WEP (B) is the weakest option - it was cryptographically broken over two decades ago and provides no meaningful security.
Memory tip: "Government = Enterprise-grade." Any time a question involves high-security or government requirements, map it to 802.1X (RADIUS-based, individual authentication) - the "enterprise" mode of WPA. The higher the stakes, the further you go from shared keys (WEP → PSK → PPSK → 802.1X).
Topics
Community Discussion
No community discussion yet for this question.