Cisco CCNA (200-301)Security FundamentalsMedium

A company wants each wireless employee to authenticate using their individual Active Directory username and password, with authentication centrally validated by a RADIUS server, rather than using one shared passphrase for the whole office. Which wireless security mode should be configured on the access points?

  1. AOpen authentication with MAC address filtering
  2. BWEP with shared key authentication
  3. CWPA2-Enterprise
  4. DWPA2-Personal
Show answer & explanation

Correct answer: C. WPA2-Enterprise

WPA2-Enterprise uses 802.1X authentication, requiring each user to authenticate individually against a RADIUS server (often integrated with Active Directory), rather than relying on a single shared pre-shared key as used in WPA2-Personal.

Why the other options are wrong

  • A. MAC filtering does not authenticate users and is easily bypassed by spoofing.
  • B. WEP is an outdated, insecure protocol and does not support centralized per-user authentication.
  • D. WPA2-Personal uses a single shared pre-shared key (PSK) for all users, not individual credentials.

WPA2-Enterprise (802.1X)

WPA2-Enterprise uses 802.1X authentication with a RADIUS server to authenticate each user individually, typically integrated with a directory service like Active Directory.

  • Requires a RADIUS/AAA server for authentication
  • Each user has unique credentials, unlike shared PSK
  • Commonly used in corporate/enterprise environments

Memory trick: Enterprise = everyone logs in individually via RADIUS.

More Security Fundamentals questions