H12-323_V2.0 · Question #142
A large enterprise needs to deploy a WLAN network. In order to achieve secure isolation between employee access and guest access, the Navi AC networking architecture is adopted. At the same time…
The correct answer is B. 802.1X authentication. 802.1X cannot be selected because it is fundamentally incompatible with an "Open" security policy. 802.1X (WPA/WPA2-Enterprise) requires an encrypted wireless security mode to function - it operates by dynamically generating and distributing encryption keys (via EAP/RADIUS)…
Question
A large enterprise needs to deploy a WLAN network. In order to achieve secure isolation between employee access and guest access, the Navi AC networking architecture is adopted. At the same time, when the enterprise engineer configures user authentication, the security policy is set to Open. Which of the following cannot be selected when configuring the authentication method?
Options
- ABuilt-in Portal authentication
- B802.1X authentication
- CExternal Portal Authentication
- DMAC Authentication
How the community answered
(40 responses)- A15% (6)
- B73% (29)
- C5% (2)
- D8% (3)
Explanation
802.1X cannot be selected because it is fundamentally incompatible with an "Open" security policy. 802.1X (WPA/WPA2-Enterprise) requires an encrypted wireless security mode to function - it operates by dynamically generating and distributing encryption keys (via EAP/RADIUS) during authentication. When security is set to Open (no Layer 2 encryption), the AC/AP has no encrypted channel for 802.1X to negotiate, so the system explicitly blocks it as a selectable option.
Why the distractors are wrong:
- A (Built-in Portal) and C (External Portal) both work at Layer 3 - they redirect users to a web login page regardless of Layer 2 encryption state, making them fully compatible with Open security.
- D (MAC Authentication) authenticates devices by their hardware address, which is a Layer 2 check that does not depend on encryption being enabled.
Memory tip: Think of 802.1X as needing a "locked room" (encryption) to hand over the key - if the room is already "Open," there's nothing for 802.1X to lock or unlock. Portal and MAC auth are guards who can work with the door open or closed.
Topics
Community Discussion
No community discussion yet for this question.