N10-009 exam dumps

N10-009 practice question 277 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 277

Single answerKey management

A company uses WPA2-Enterprise for employee laptops and phones, but the guest wireless network still uses WPA2-Personal with a shared pre-shared key (PSK). After a contractor leaves, the network administrator is told to prevent the former contractor from reconnecting to the guest network without disrupting employee authentication. The administrator also wants to reduce the effort required for future guest access changes. Which action is the BEST solution from a key management perspective?

  1. A

    Change the guest network PSK and provide the new key only to current approved guests

  2. B

    Change the WPA2-Enterprise RADIUS shared secret used by employee authentication servers

  3. C

    Reissue the digital certificates used by employee devices on the corporate wireless network

  4. D

    Lower the guest wireless signal strength so the former contractor cannot connect from outside the building

Show answer and explanation

Correct answer: A

Explanation

The key management issue in this scenario is that WPA2-Personal relies on a shared secret known by multiple users. Once that PSK has been disclosed to someone who should no longer have access, the standard corrective action is to rotate the PSK and redistribute it to authorized users. By contrast, WPA2-Enterprise provides per-user or per-device authentication through 802.1X and a RADIUS server, which significantly improves key and credential management because access can usually be revoked at the individual account or certificate level without changing credentials for everyone else. This is why organizations often prefer enterprise authentication for managed users and reserve PSKs only for limited guest use cases. Best practices from wireless security guidance and vendor documentation consistently recommend changing shared keys when personnel with knowledge of them leave and minimizing long-term reliance on broadly shared PSKs.

  • A. Correct.

    Correct. A WPA2-Personal guest network uses a single shared pre-shared key, so if a former guest or contractor knows that key, the practical way to revoke access is to change the PSK and redistribute it only to authorized users. This directly addresses key management on the guest SSID without affecting the separate WPA2-Enterprise environment used by employees. Although rotating and redistributing a PSK can be administratively burdensome, it is the appropriate action when access must be revoked on a PSK-based network.

  • B. Incorrect.

    Incorrect. The RADIUS shared secret is used between the wireless infrastructure and the authentication server in a WPA2-Enterprise deployment; it is not the guest's WPA2-Personal key. Changing it would affect enterprise authentication components and could disrupt employee access, but it would not specifically solve the problem of a contractor who knows the guest PSK.

  • C. Incorrect.

    Incorrect. Reissuing employee certificates applies to certificate-based enterprise authentication, such as EAP-TLS, and is unrelated to a guest network that uses a shared PSK. This option reflects a common misconception that all wireless access control issues are solved through certificate changes, even when the affected SSID uses a different authentication model.

  • D. Incorrect.

    Incorrect. Reducing signal strength is not a key management control and does not reliably prevent a known user from reconnecting if they are still within range. It also may negatively affect legitimate guest coverage. This is a physical/radio tuning change, not a solution for revoking knowledge of a compromised or over-shared wireless key.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam