nerdexam
HP

HPE7-A08 · Question #95

A network administrator wants to configure an 802.1X supplicant for a wireless network that includes the following: AES encryption EAP-MSCHAPv2-based user and machine authentication Validation of…

The correct answer is A. Enable server certificate validation B. Enable user authentication. After setting up PEAP and enabling user/machine authentication, the two remaining requirements from the spec are server certificate validation and inner EAP method configuration for user auth - both handled inside the PEAP Properties dialog. Option A (Enable server certificate…

Perform HPE Aruba Networking CX Switch Configurations

Question

A network administrator wants to configure an 802.1X supplicant for a wireless network that includes the following:

AES encryption EAP-MSCHAPv2-based user and machine authentication Validation of server certificate in Microsoft Windows 10 The network administrator creates a WLAN profile and selects the Change connection settings option. Then the network administrator changes the security type to Microsoft: Protected EAP (PEAP) and enables user and machine authentication under Additional Settings. What must the network administrator do next to accomplish the task? (Select two)

Options

  • AEnable server certificate validation
  • BEnable user authentication
  • CEAP-TLS-based user and machine authentication
  • DChange default RC4 encryption for AES

How the community answered

(25 responses)
  • A
    84% (21)
  • C
    12% (3)
  • D
    4% (1)

Explanation

After setting up PEAP and enabling user/machine authentication, the two remaining requirements from the spec are server certificate validation and inner EAP method configuration for user auth - both handled inside the PEAP Properties dialog. Option A (Enable server certificate validation) directly addresses the explicit requirement to validate the RADIUS server's certificate, preventing man-in-the-middle attacks. Option B (Enable user authentication) is needed to activate EAP-MSCHAPv2 as the inner authentication method within the PEAP tunnel, which handles the credential-based user auth the spec calls for.

Why C is wrong: EAP-TLS authenticates using client certificates, not usernames and passwords - it's a completely different inner method than EAP-MSCHAPv2, which the scenario explicitly requires.

Why D is wrong: AES/CCMP encryption is a wireless-layer setting (WPA2) configured when selecting the security type - that step was already completed. There is no RC4-to-AES swap happening inside the PEAP supplicant settings; this option conflates two unrelated configuration layers.

Memory tip: After PEAP is selected, think "Secure the server, Secure the user" - you must (1) Switch on server cert validation and (2) Set up the inner user-auth method (MSCHAPv2). Everything else is either done already or the wrong EAP method entirely.

Topics

#802.1X supplicant#EAP-MSCHAPv2#PEAP#server certificate validation

Community Discussion

No community discussion yet for this question.

Full HPE7-A08 Practice