SY0-701 exam dumps

SY0-701 practice question 206 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 206

Single answerPort security: 802.1X , Extensible Authentication Protocol (EAP)

A company is deploying 802.1X port-based access control on access switches to prevent unauthorized devices from connecting to the internal network. The environment includes company-managed laptops joined to Active Directory, a RADIUS server with an internal PKI, and a small number of legacy devices that do not support user password prompts during network authentication. The security administrator wants the strongest protection against credential theft and rogue devices while still using a standards-based EAP method that works well with certificates. Which solution should the administrator implement for the managed laptops?

  1. A

    Configure EAP-TLS so both the client and the authentication server use certificates for mutual authentication

  2. B

    Configure PEAP-MS-CHAPv2 so users authenticate with usernames and passwords only, eliminating the need for certificates

  3. C

    Disable 802.1X and use MAC filtering on the switch because it is easier to manage for corporate laptops

  4. D

    Use an open port configuration and rely on DHCP snooping to verify that only authorized laptops receive addresses

Show answer and explanation

Correct answer: A

Explanation

The best answer is EAP-TLS. In 802.1X, the switch acts as the authenticator, the endpoint acts as the supplicant, and a backend authentication server such as RADIUS validates credentials. When the requirement is strongest protection against credential theft and rogue devices, certificate-based mutual authentication is preferred over password-based approaches. EAP-TLS is a standards-based EAP method designed for this purpose and is commonly recommended in enterprise environments that already have a PKI. By contrast, PEAP-MS-CHAPv2 is still widely used but depends on passwords, which are more susceptible to theft, phishing, and replay-related attacks if the environment is not carefully managed. MAC filtering and DHCP snooping do not replace 802.1X authentication. This aligns with common enterprise guidance from IEEE 802.1X standards and vendor best practices from sources such as Microsoft, Cisco, and Aruba for certificate-based network access control.

  • A. Correct.

    Correct. EAP-TLS is widely regarded as one of the strongest EAP methods for 802.1X because it uses certificate-based mutual authentication between the supplicant and the authentication server, typically via RADIUS. This reduces the risk of credential theft associated with password-based methods and helps validate both the client and the server. In a managed enterprise with Active Directory and an internal PKI, certificate deployment is practical and aligns well with best practices for secure network access control.

  • B. Incorrect.

    Incorrect. PEAP-MS-CHAPv2 is a common 802.1X deployment choice and does protect the password exchange inside a TLS tunnel, but it still relies on password-based user authentication. That makes it weaker than certificate-based EAP-TLS in environments where the goal is strongest protection against credential theft. Someone might choose this because it is easier to deploy than full client certificates, but it does not best meet the requirement for maximum security.

  • C. Incorrect.

    Incorrect. MAC filtering is not a strong security control for enterprise port access because MAC addresses can be spoofed easily. It does not provide the identity assurance or mutual authentication that 802.1X with EAP methods provides. An administrator might consider it for simplicity, especially for non-802.1X-capable devices, but it is not the right solution for managed laptops when stronger standards-based options are available.

  • D. Incorrect.

    Incorrect. DHCP snooping is useful for mitigating rogue DHCP server attacks and improving network trust for DHCP messages, but it does not authenticate endpoints at the switch port in the way 802.1X does. Opening the port and relying on DHCP controls would not prevent unauthorized devices from attempting network access. This option confuses infrastructure protection with endpoint authentication.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam