N10-009 exam dumps

N10-009 practice question 169 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 169

Single answerEncryption: Wi-Fi Protected Access 2 (WPA2), WPA3

A company is upgrading its wireless network in a shared office building. The security team wants to reduce the risk of attackers capturing the Wi-Fi password through offline cracking and also wants stronger protection for users on the guest network. However, several older barcode scanners used in the warehouse only support WPA2-Personal. Which action should the network administrator take to best meet these requirements while maintaining compatibility?

  1. A

    Configure all SSIDs to use WPA2-Personal with TKIP so the older scanners can connect and the guest network remains broadly compatible

  2. B

    Configure a single SSID in WPA3-Personal transition mode for all users and devices, including guests and warehouse scanners

  3. C

    Create a WPA3-Personal SSID for employee and guest access, and a separate WPA2-Personal SSID only for the legacy scanners

  4. D

    Disable encryption on the guest SSID and rely on a captive portal, while using WPA2-Personal for employees and scanners

Show answer and explanation

Correct answer: C

Explanation

The best answer is to deploy WPA3-Personal for users who support it and isolate legacy WPA2-only devices onto their own SSID. In real environments, this is a common design choice when older hardware cannot be upgraded but the organization still wants improved wireless security for the majority of clients. WPA3-Personal replaces the WPA2-Personal pre-shared key authentication exchange with SAE (Simultaneous Authentication of Equals), which is designed to provide stronger resistance to offline password-guessing attacks. By contrast, keeping all devices on WPA2-Personal preserves compatibility but does not meet the stated security objective as well. Using TKIP is not recommended because modern best practice for WPA2 is AES/CCMP, and disabling encryption on a guest network is weaker still. This aligns with Wi-Fi Alliance guidance on WPA3 adoption and common enterprise best practices of segmenting legacy devices rather than lowering the security posture of the entire WLAN.

  • A. Incorrect.

    This is incorrect. TKIP is deprecated and was associated with older WPA implementations, not a best-practice choice for modern deployments. WPA2 should use AES/CCMP, not TKIP. Using WPA2-Personal everywhere also does not address the requirement to reduce the risk of offline password cracking in the way WPA3-Personal does with SAE.

  • B. Incorrect.

    This is incorrect. WPA3 transition mode can help mixed environments, but using one shared SSID for all users and legacy devices weakens the security goal because WPA2-capable devices may still associate using WPA2 instead of WPA3. It also does not separate legacy scanner risk from employee and guest traffic. The scenario calls for stronger protection for most users while preserving compatibility for a limited set of older devices.

  • C. Correct.

    This is correct. WPA3-Personal uses SAE instead of the WPA2-Personal PSK exchange, which provides better resistance to offline dictionary attacks and stronger protections for modern clients. Creating a separate WPA2-Personal SSID only for the legacy scanners limits exposure from older security capabilities while allowing employees and guests to use the stronger WPA3-based network.

  • D. Incorrect.

    This is incorrect. A captive portal does not replace link-layer encryption. An open guest network with only a portal leaves wireless traffic exposed prior to any higher-layer protections and does not meet the requirement for stronger guest protection. WPA3 or at least properly configured WPA2 would be more appropriate than removing Wi-Fi encryption.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam