nerdexam
CompTIA

SY0-501 · Question #504

A security analyst is hardening a WiFi infrastructure. The primary requirements are the following: The infrastructure must allow staff to authenticate using the most secure method. The…

The correct answer is D. Configure a captive portal for guest and WPA2 Enterprise for staff. To meet the requirements, the security analyst should recommend WPA2 Enterprise for staff authentication due to its superior security, and a captive portal for guests to facilitate email-based access logging.

Submitted by yuki_2020· Mar 4, 2026Security architecture

Question

A security analyst is hardening a WiFi infrastructure. The primary requirements are the following:

The infrastructure must allow staff to authenticate using the most secure method. The infrastructure must allow guests to use an "open" WiFi network that logs valid email addresses before granting access to the Internet. Given these requirements, which of the following statements BEST represents what the analyst should recommend and configure?

Options

  • AConfigure a captive portal for guests and WPS for staff.
  • BConfigure a captive portal for staff and WPA for guests.
  • CConfigure a captive portal for staff and WEP for guests.
  • DConfigure a captive portal for guest and WPA2 Enterprise for staff.

How the community answered

(58 responses)
  • A
    7% (4)
  • B
    2% (1)
  • C
    12% (7)
  • D
    79% (46)

Why each option

To meet the requirements, the security analyst should recommend WPA2 Enterprise for staff authentication due to its superior security, and a captive portal for guests to facilitate email-based access logging.

AConfigure a captive portal for guests and WPS for staff.

WPS (Wi-Fi Protected Setup) is a convenience feature with known security vulnerabilities and is not considered the most secure authentication method for staff.

BConfigure a captive portal for staff and WPA for guests.

A captive portal is unsuitable for primary staff authentication, and WPA (likely WPA-PSK) requires a pre-shared key, contradicting the 'open' network requirement for guests.

CConfigure a captive portal for staff and WEP for guests.

A captive portal is inappropriate for staff's primary secure authentication, and WEP is an outdated, highly insecure encryption protocol that should never be used.

DConfigure a captive portal for guest and WPA2 Enterprise for staff.Correct

WPA2 Enterprise, leveraging 802.1X and a RADIUS server, provides robust, individual user authentication and strong encryption, making it the most secure method for staff. A captive portal fulfills the guest requirement by redirecting users to a web page for email registration before granting Internet access over an otherwise 'open' network.

Concept tested: Wi-Fi security protocols, authentication methods, and guest access solutions

Source: https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-802-1x-configure-nps

Topics

#WPA2 Enterprise#captive portal#wireless security#authentication protocols

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice