HPE7-A08 · Question #95
A network administrator wants to configure an 802.1X supplicant for a wireless network that includes the following: AES encryption EAP-MSCHAPv2-based user and machine authentication Validation of…
The correct answer is A. Enable server certificate validation B. Enable user authentication. After setting up PEAP and enabling user/machine authentication, the two remaining requirements from the spec are server certificate validation and inner EAP method configuration for user auth - both handled inside the PEAP Properties dialog. Option A (Enable server certificate…
Question
A network administrator wants to configure an 802.1X supplicant for a wireless network that includes the following:
AES encryption EAP-MSCHAPv2-based user and machine authentication Validation of server certificate in Microsoft Windows 10 The network administrator creates a WLAN profile and selects the Change connection settings option. Then the network administrator changes the security type to Microsoft: Protected EAP (PEAP) and enables user and machine authentication under Additional Settings. What must the network administrator do next to accomplish the task? (Select two)
Options
- AEnable server certificate validation
- BEnable user authentication
- CEAP-TLS-based user and machine authentication
- DChange default RC4 encryption for AES
How the community answered
(25 responses)- A84% (21)
- C12% (3)
- D4% (1)
Explanation
After setting up PEAP and enabling user/machine authentication, the two remaining requirements from the spec are server certificate validation and inner EAP method configuration for user auth - both handled inside the PEAP Properties dialog. Option A (Enable server certificate validation) directly addresses the explicit requirement to validate the RADIUS server's certificate, preventing man-in-the-middle attacks. Option B (Enable user authentication) is needed to activate EAP-MSCHAPv2 as the inner authentication method within the PEAP tunnel, which handles the credential-based user auth the spec calls for.
Why C is wrong: EAP-TLS authenticates using client certificates, not usernames and passwords - it's a completely different inner method than EAP-MSCHAPv2, which the scenario explicitly requires.
Why D is wrong: AES/CCMP encryption is a wireless-layer setting (WPA2) configured when selecting the security type - that step was already completed. There is no RC4-to-AES swap happening inside the PEAP supplicant settings; this option conflates two unrelated configuration layers.
Memory tip: After PEAP is selected, think "Secure the server, Secure the user" - you must (1) Switch on server cert validation and (2) Set up the inner user-auth method (MSCHAPv2). Everything else is either done already or the wrong EAP method entirely.
Topics
Community Discussion
No community discussion yet for this question.