220-1102 exam dumps

220-1102 practice question 399 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 399

Single answerRemote Authentication Dial-in User Service (RADIUS)

A small business uses WPA2-Enterprise for its office Wi-Fi so employees can sign in with their company usernames and passwords. After replacing the wireless access point, users can see the SSID and enter their credentials, but authentication fails for every employee. Internet access works if the technician temporarily switches the SSID to WPA2-Personal with a shared passphrase. The RADIUS server is online, and no user accounts are locked out. Which of the following is the MOST likely cause of the WPA2-Enterprise failure?

  1. A

    The new access point was not configured with the correct shared secret for the RADIUS server

  2. B

    The DHCP scope does not have enough available IP addresses for wireless clients

  3. C

    The DNS server does not have a host record for the wireless SSID

  4. D

    The employee passwords must be manually synchronized to the access point

Show answer and explanation

Correct answer: A

Explanation

This scenario tests practical understanding of how RADIUS is used with WPA2-Enterprise/802.1X wireless authentication. When users can connect with WPA2-Personal but all WPA2-Enterprise logins fail after an AP replacement, the most likely issue is the trust relationship between the new AP and the RADIUS server, especially the shared secret, RADIUS server IP/port, or client definition on the RADIUS server. Of those, the shared secret mismatch is the most common and best answer here. In standard practice, the wireless AP forwards authentication requests to the RADIUS server, which validates the user's credentials and returns an accept or reject response. DHCP and DNS are separate services and do not perform user authentication. Best-practice vendor and standards documentation for 802.1X and RADIUS deployments consistently notes that each network access server/client device must be defined on the RADIUS server with the correct IP address and matching shared secret.

  • A. Correct.

    Correct. In a WPA2-Enterprise deployment, the access point or wireless controller typically acts as the authenticator and forwards authentication requests to the RADIUS server. The AP and RADIUS server must share a matching RADIUS shared secret. If the AP was replaced and that shared secret was not entered correctly, all 802.1X/RADIUS authentications can fail even though the server is online and users are entering valid credentials.

  • B. Incorrect.

    Incorrect. DHCP issues affect address assignment after a client successfully associates and authenticates, not the initial RADIUS authentication step. A depleted DHCP scope would cause problems obtaining an IP address, but it would not typically cause every user credential attempt to fail at the sign-in stage.

  • C. Incorrect.

    Incorrect. DNS does not need a host record for an SSID. An SSID is a wireless network name, not a DNS hostname. While DNS problems can affect application access after connectivity is established, they would not prevent WPA2-Enterprise authentication against a RADIUS server.

  • D. Incorrect.

    Incorrect. In a RADIUS-based WPA2-Enterprise environment, employee passwords are generally stored and validated through a centralized identity source, such as a directory service or local RADIUS user database, not manually synchronized to each access point. This option reflects a common misunderstanding between enterprise authentication and shared-password wireless setups.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam