N10-009 exam dumps

N10-009 practice question 278 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 278

Single answerKey management

A network administrator is deploying WPA3-Enterprise for a new corporate wireless network. The company wants to reduce the administrative overhead of manually replacing long-term encryption keys and ensure that if one session key is compromised, past and future user sessions remain protected. Which solution best meets these requirements?

  1. A

    Implement a RADIUS server to perform 802.1X authentication and dynamically generate unique session keys for each client session

  2. B

    Configure a single strong pre-shared key (PSK) and rotate it quarterly on all access points and client devices

  3. C

    Use MAC filtering so only approved devices can join the WLAN, while keeping one shared encryption key for all users

  4. D

    Install a captive portal to require user logon before granting access to a wireless network that uses a shared WPA2 passphrase

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use WPA3-Enterprise with 802.1X authentication through a RADIUS server because enterprise wireless security is designed to handle key management at scale. Instead of distributing and periodically replacing one shared key, 802.1X authenticates users or devices individually and supports dynamic generation of session-specific encryption keys. This reduces operational overhead and limits the impact of a compromised key to a single session rather than all users. These principles align with wireless security best practices described by the Wi-Fi Alliance for WPA3-Enterprise and IEEE 802.1X/EAP-based authentication models. In Network+ terms, strong key management emphasizes minimizing shared secrets, automating key lifecycle processes where possible, and using per-user or per-session keying to improve confidentiality.

  • A. Correct.

    Correct. WPA3-Enterprise uses 802.1X authentication, typically backed by a RADIUS server, to authenticate each user or device individually and derive dynamic session keys rather than relying on one long-term shared key. This approach reduces the burden of manually changing a shared key across the entire environment and improves key management by limiting exposure if a session key is compromised. Per-user/per-session keying is a core advantage of enterprise wireless security.

  • B. Incorrect.

    Incorrect. Rotating a PSK quarterly is better than leaving one key in place indefinitely, but it still relies on a single shared secret known by many users and devices. That creates significant administrative overhead whenever the key changes and does not provide the same per-session key isolation as WPA3-Enterprise with 802.1X.

  • C. Incorrect.

    Incorrect. MAC filtering is not a key management solution. MAC addresses can be spoofed, and using MAC filtering with a shared key does nothing to address the problem of replacing long-term keys or isolating session exposure. This option reflects the common misconception that access control lists can replace proper authentication and dynamic keying.

  • D. Incorrect.

    Incorrect. A captive portal controls user access after association to the wireless network, but it does not solve the underlying encryption key management issue. If the SSID still uses a shared WPA2 passphrase, all users continue to depend on the same long-term key, which does not meet the requirement for reduced key replacement overhead and stronger session isolation.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam