SY0-701 exam dumps

SY0-701 practice question 267 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 267

Single answer

A security administrator is upgrading a corporate wireless network used by employee laptops and tablets. The organization wants to eliminate shared Wi-Fi passwords, use per-user authentication tied to the company directory, and provide stronger protection against offline password-guessing attacks than the old WPA2 deployment. Some legacy devices will be moved to a separate network. Which configuration BEST meets these requirements?

  1. A

    Configure WPA3-Enterprise with 802.1X authentication and a RADIUS server backed by the corporate directory

  2. B

    Configure WPA3-Personal with SAE and distribute the passphrase through the company password manager

  3. C

    Configure WPA2-Enterprise with a pre-shared key and local authentication on each access point

  4. D

    Configure WEP with 802.1X and a RADIUS server to centralize authentication

Show answer and explanation

Correct answer: A

Explanation

The best answer is WPA3-Enterprise with 802.1X and a RADIUS server. The scenario requires three things: no shared Wi-Fi password, per-user authentication linked to a directory, and stronger protection than the older WPA2 deployment. WPA3-Enterprise addresses enterprise wireless access control needs by using centralized AAA through RADIUS and authentication protocols within the 802.1X framework, typically with EAP methods such as EAP-TLS or PEAP depending on the organization's design. This supports individual accountability, easier revocation, and centralized policy enforcement. WPA3-Personal with SAE improves resistance to offline password guessing compared to WPA2-PSK, but it still uses a shared credential and therefore does not meet the per-user authentication requirement. WEP is deprecated by industry best practices and should not be used. Guidance from the Wi-Fi Alliance and NIST wireless security recommendations aligns with selecting WPA3-Enterprise for modern enterprise WLANs that require strong authentication and centralized access control.

  • A. Correct.

    Correct. WPA3-Enterprise is designed for enterprise environments that need centralized AAA services and per-user authentication. In practice, this is commonly implemented with 802.1X as the authentication framework and RADIUS as the backend AAA protocol, often integrated with Active Directory or another enterprise identity store. This removes the need for a shared Wi-Fi password and supports strong cryptographic protections appropriate for business wireless networks.

  • B. Incorrect.

    Incorrect. WPA3-Personal uses SAE (Simultaneous Authentication of Equals), which is stronger than WPA2-PSK against offline dictionary attacks, but it still relies on a shared password rather than per-user authentication. That means it does not meet the requirement to eliminate shared Wi-Fi passwords or tie access directly to individual directory accounts.

  • C. Incorrect.

    Incorrect. WPA2-Enterprise does support 802.1X with RADIUS, but this option is internally inconsistent because it mentions a pre-shared key and local authentication on each access point. Enterprise mode does not use a PSK for client authentication, and local authentication on each AP would not satisfy the goal of centralized AAA tied to the corporate directory.

  • D. Incorrect.

    Incorrect. WEP is obsolete and insecure due to well-known cryptographic weaknesses. Even if paired with 802.1X and RADIUS, WEP does not provide acceptable wireless confidentiality or integrity protection for modern enterprise use. Security+ expects candidates to recognize WEP as deprecated and unsuitable.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam