0364
A wireless network has the following design requirements:
- Authentication must not be dependent on enterprise directory service
- It must allow background reconnection for mobile users
- It must not depend on user certificates
Which of the following should be used in the design to meet the requirements? (Choose two.)
(The term “background reconnection” does not exist in any WiFi documentation; PEAP does
support “fast reconnect” while roaming - it is a bit unclear what CompTIA means here)
Answer
PEAP
Open Systems Authentication
PSK
EAP-TLS
Captive portals
Card 22
Question
0420
A security engineer is configuring a wireless network with EAP-TLS. Which of the following activities is a requirement for this configuration?
Answer
Setting up a TACACS+ server
Configuring federation between authentication servers
Enabling TOTP
Deploying certificates to endpoint devices
Card 23
Question
0461
A systems administrator wants to implement a wireless protocol that will allow the organization to authenticate
mobile devices prior to providing the user with a captive portal Iogin.
Which of the following should the systems administrator configure?
Answer
L2TP with MAC filtering
EAP-TTLS
WPA2-CCMP with PSK
RADIUS federation
Card 24
Question
0501
A security analyst is hardening a WiFi infrastructure.
The primary requirements are the following:
- The infrastructure must allow staff to authenticate using the most secure method.
- The infrastructure must allow guests to use an "open" WiFi network that logs valid
email addresses before granting access to the Internet.
Given these requirements, which of the following statements BEST represents what the analyst should recommend and configure?
Answer
Configure a captive portal for guests and WPS for staff.
Configure a captive portal for staff and WPA for guests.
Configure a captive portal for staff and WEP for guests.
Configure a captive portal for guest and WPA2 Enterprise for staff
Card 25
Question
0545
An instructor is teaching a hands-on wireless security class and needs to configure a test access point to show students an attack on a weak protocol.
Which of the following configurations should the instructor implement?
Answer
WPA2
WPA
WEP
EAP
Card 26
Question
0546
A security analyst is hardening a large-scale wireless network. The primary requirements are the following:
- Must use authentication through EAP-TLS certificates
- Must use an AAA server
- Must use the most secure encryption protocol
Given these requirements, which of the following should the analyst implement and recommend? (Select TWO.)
Answer
802.1X
LDAP
802.3
TKIP
WPA2-PSK
CCMP
Card 27
Question
0589
A security administrator is performing a risk assessment on a legacy WAP with a WEP-enabled wireless infrastructure.
Which of the following should be implemented to harden the infrastructure without upgrading the
WAP?
Answer
Implement WPA and TKIP
Implement WEP and RC4
Implement WPS and an eight-digit pin
Implement WPA2 Enterprise
Card 28
Question
0620
A company needs to implement a system that only lets a visitor use the company's network infrastructure if the visitor accepts the AUP.
Which of the following should the company use?
Answer
WiFi-protected setup
Password authentication protocol
Captive portal
RADIUS
Card 29
Question
0636
A security analyst is specifying requirements for a wireless network. The analyst must explain the security features Key rotationprovided by various architecture choices.
Which of the following is provided by PEAP, EAP-TLS, and EAP-TTLS?
Answer
Key rotation
Secure hashing
Mutual authentication
Certificate pinning
Card 30
Question
0653
A company wants to implement a wireless network with the following requirements:
- All wireless users will have a unique credential.
- User certificates will not be required for authentication.
- The company's AAA infrastructure must be utilized.
- Local hosts should not store authentication tokens.
Which of the following should be used in the design to meet the requirements?
Answer
EAP-TLS
WPS
PSK
PEAP
Card 31
Question
0656
A security administrator is configuring a RADIUS server for wireless authentication. The configuration must ensure client credentials are encrypted end-to-end between the client and the authenticator.
Which of the following protocols should be configured on the RADIUS server? (Choose two.)
Answer
PAP
MSCHAP
PEAP
NTLM
SAML
Card 32
Question
0671
A company utilizes 802.11 for all client connectivity within a facility. Users in one part of the building are reporting they are unable to access company resources when connected to the company SSID.
Which of the following should the security administrator use to assess connectivity?
Answer
Sniffer
Honeypot
Wireless scanner
Routing tables
Card 33
Question
0712
A systems administrator needs to integrate multiple IoT and small embedded devices into the company's wireless
network securely. Which of the following should the administrator implement to ensure low-power and legacy
devices can connect to the wireless network?
Answer
WPS
WPA
EAP-FAST
802.1X
Card 34
Question
0806
An organization wants to set up a wireless network in the most secure way. Budget is not a major consideration, and the organization is willing to accept some complexity when clients are connecting. It is also willing to deny Enable WPA2-PSK for older clients and WPA2-Enterprise for all other clients.wireless connectivity for clients who cannot be connected in the most secure manner.
Which of the following would be the MOST secure setup that conforms to the organization's requirements?
Answer
Enable WPA2-PSK for older clients and WPA2-Enterprise for all other clients.
Enable WPA2-PSK, disable all other modes, and implement MAC filtering along with port security.
Use WPA2-Enterprise with RADIUS and disable pre-shared keys.
Use WPA2-PSK with a 24-character complex password and change the password monthly.
Card 35
Question
0821
A systems engineer is setting up a RADIUS server to support a wireless network that uses certificate authentication.
Which of the following protocols must be supported by both the RADIUS server and the WAPs?
Answer
CCMP
TKIP
WPS
EAP
Card 36
Question
0823
A systems engineer is configuring a wireless network. The network must not require installation of third-party software. Mutual authentication of the client and the server must be used. The company has an internal PKI.
Which of the following configurations should the engineer choose?
Answer
EAP-TTLS
EAP-TLS
PEAP
EAP-FAST
EAP-MD5
Card 37
Question
0868
Which of the following attacks is used to capture the WPA2 handshake?
Answer
Replay
Evil twin
IV
Disassociation
Card 38
Question
0885
A local coffee shop runs a small WiFi hotspot for its customers that utilizes WPA2-PSK. The coffee shop would like WEPto stay current with security trends and wants to implement WPA3 to make its WiFi even more secure.
Which of the following technologies should the coffee shop use in place of PSK?
Answer
WEP
SAE (Simultaneous Authentication of Equals, a WPA3 feature)
WPS
EAP
Card 39
Question
0913
A network administrator is setting up wireless access points in all the conference rooms and wants to authenticate devices using PKI.
Which of the following should the administrator configure?
Answer
A captive portal
802.1X
PSK
WPS
Card 40
Question
0961
A coffee company has hired an IT consultant to set up a WiFi network that will provide Internet access to customers who visit the company's chain of cafés. The coffee company has provided no requirements other than that customers should be granted access after registering via a web form and accepting the terms of service.
Which of the following is the MINIMUM acceptable configuration to meet this single requirement?
Answer
Captive portal
Open WiFi
WPA with PSK
WPS
How to use this set
Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.