nerdexam
CompTIA

SY0-501 · Question #38

A company is currently using the following configuration: IAS server with certificate-based EAP-PEAP and MSCHAP Unencrypted authentication via PAP A security administrator needs to configure a new…

The correct answer is A. PAP C. MSCHAP. This question tests understanding of authentication protocols used in the described wireless configuration, specifically identifying that the legacy IAS setup uses PAP for unencrypted authentication and MSCHAP within the EAP-PEAP tunnel.

Submitted by sofia.br· Mar 4, 2026Security architecture

Question

A company is currently using the following configuration:

  • IAS server with certificate-based EAP-PEAP and MSCHAP
  • Unencrypted authentication via PAP

A security administrator needs to configure a new wireless setup with the following configurations:

  • PAP authentication method
  • PEAP and EAP provide two-factor authentication

Which of the following forms of authentication are being used? (Select TWO).

Options

  • APAP
  • BPEAP
  • CMSCHAP
  • DPEAP-MSCHAP
  • EEAP
  • FEAP-PEAP

How the community answered

(48 responses)
  • A
    81% (39)
  • B
    2% (1)
  • D
    2% (1)
  • E
    4% (2)
  • F
    10% (5)

Why each option

This question tests understanding of authentication protocols used in the described wireless configuration, specifically identifying that the legacy IAS setup uses PAP for unencrypted authentication and MSCHAP within the EAP-PEAP tunnel.

APAPCorrect

PAP (Password Authentication Protocol) is explicitly stated as the unencrypted authentication method in use by the IAS server configuration, making it one of the active authentication forms being used in the described environment.

BPEAP

PEAP alone is not selected because the question identifies PEAP as part of a tunneling mechanism (EAP-PEAP) rather than a standalone authentication form in this specific configuration.

CMSCHAPCorrect

MSCHAP is the inner authentication protocol used within the EAP-PEAP tunnel in the IAS server configuration (EAP-PEAP with MSCHAP), meaning it is the underlying credential validation method that authenticates the user's identity inside the encrypted PEAP tunnel.

DPEAP-MSCHAP

PEAP-MSCHAP is not listed as a discrete choice that matches the described configuration; the configuration describes EAP-PEAP with MSCHAP as separate components rather than a combined PEAP-MSCHAP label.

EEAP

EAP alone is not the correct answer because EAP is a framework, not a specific authentication method being used independently; the configuration uses EAP-PEAP as the tunneling protocol, not bare EAP.

FEAP-PEAP

EAP-PEAP describes the tunneling/encapsulation mechanism used to protect the inner authentication, but it is not itself a standalone authentication form - the actual authentication methods inside the tunnel are MSCHAP and PAP.

Concept tested: EAP-PEAP inner and outer authentication protocol identification

Source: https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-top

Topics

#wireless authentication#PAP#MSCHAP#PEAP

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice