SY0-701 exam dumps

SY0-701 practice question 256 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 256

Single answerWireless devices

A security administrator is hardening a company’s wireless network after discovering that employees can still join the corporate SSID using a shared password that was posted in a conference room months ago. Management wants to prevent unauthorized access by former employees and visitors, provide unique credentials for each user, and avoid relying on insecure legacy wireless settings. Which solution best meets these requirements?

  1. A

    Configure WPA2-Personal with a stronger pre-shared key and change it quarterly

  2. B

    Configure WPA3-Personal with SAE so the shared password is harder to crack offline

  3. C

    Configure WPA2-Enterprise or WPA3-Enterprise with 802.1X authentication backed by a RADIUS server

  4. D

    Hide the SSID and enable MAC address filtering for approved employee devices

Show answer and explanation

Correct answer: C

Explanation

The best answer is to use enterprise wireless authentication with 802.1X and a backend RADIUS server. In a business environment, this allows unique credentials for each user or device, centralized policy enforcement, and rapid revocation of access when an employee leaves. Shared-key approaches such as WPA2-Personal and WPA3-Personal are more appropriate for home or small environments but do not provide the individual accountability required here. Security best practices from Wi-Fi Alliance enterprise deployments and common guidance from NIST for enterprise network access emphasize strong authentication, centralized identity management, and avoidance of relying on obscurity controls such as hidden SSIDs or MAC filtering as primary protections.

  • A. Incorrect.

    This is incorrect. WPA2-Personal uses a single pre-shared key for all users, so it does not provide unique credentials per employee. Even if the password is stronger and rotated regularly, it still creates operational problems when employees leave or when the key is shared with guests. A shared key model does not meet the requirement to uniquely identify and control access for each user.

  • B. Incorrect.

    This is incorrect. WPA3-Personal with SAE is stronger than WPA2-Personal because it improves resistance to offline password-guessing attacks and removes some weaknesses associated with the traditional PSK exchange. However, it still relies on a shared password rather than unique user credentials. This improves cryptographic protection but does not solve the access control problem described in the scenario.

  • C. Correct.

    This is correct. WPA2-Enterprise or WPA3-Enterprise with 802.1X uses per-user authentication, typically through a RADIUS server, allowing each employee to have unique credentials or certificates. This supports revoking access for a single user without changing the entire wireless network password. It is the standard best-practice approach for corporate wireless networks that need accountability, centralized authentication, and stronger access control than shared-key wireless.

  • D. Incorrect.

    This is incorrect. Hiding the SSID does not provide meaningful security because the network name is still exposed in wireless management traffic and can be discovered easily with basic tools. MAC address filtering is also weak because MAC addresses can be spoofed. These measures may add minor administrative controls, but they do not provide strong authentication or per-user identity management.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam