Cisco CCNA (200-301)Security FundamentalsMedium
A company wants each wireless employee to authenticate using their individual Active Directory username and password, with authentication centrally validated by a RADIUS server, rather than using one shared passphrase for the whole office. Which wireless security mode should be configured on the access points?
- AOpen authentication with MAC address filtering
- BWEP with shared key authentication
- CWPA2-Enterprise
- DWPA2-Personal
Show answer & explanationAnswer & explanation
Correct answer: C. WPA2-Enterprise
WPA2-Enterprise uses 802.1X authentication, requiring each user to authenticate individually against a RADIUS server (often integrated with Active Directory), rather than relying on a single shared pre-shared key as used in WPA2-Personal.
Why the other options are wrong
- A. MAC filtering does not authenticate users and is easily bypassed by spoofing.
- B. WEP is an outdated, insecure protocol and does not support centralized per-user authentication.
- D. WPA2-Personal uses a single shared pre-shared key (PSK) for all users, not individual credentials.
WPA2-Enterprise (802.1X)
WPA2-Enterprise uses 802.1X authentication with a RADIUS server to authenticate each user individually, typically integrated with a directory service like Active Directory.
- Requires a RADIUS/AAA server for authentication
- Each user has unique credentials, unlike shared PSK
- Commonly used in corporate/enterprise environments
Memory trick: Enterprise = everyone logs in individually via RADIUS.