CompTIA Network+ (N10-009)Network SecurityHard
A security engineer is configuring 802.1X for a corporate wireless network and wants both the client and the authentication server to mutually verify each other using digital certificates, eliminating the risk of credential theft via a fake authentication portal. Which EAP method should be selected?
- AEAP-MD5
- BLEAP
- CPEAP
- DEAP-TLS
Show answer & explanationAnswer & explanation
Correct answer: D. EAP-TLS
EAP-TLS requires certificates on both the client and server, providing mutual authentication and eliminating password-based credential theft, unlike PEAP (which typically only authenticates the server via certificate while clients use credentials), EAP-MD5 (weak, no mutual auth, vulnerable to offline attacks), and LEAP (deprecated Cisco proprietary method with known weaknesses).
Why the other options are wrong
- A. EAP-MD5 offers one-way, weak hash-based authentication with no mutual certificate verification.
- B. LEAP is a deprecated, vulnerable proprietary EAP method.
- C. PEAP typically authenticates only the server via certificate, client uses credentials inside the tunnel.
EAP-TLS
An 802.1X EAP method requiring digital certificates on both the client and authentication server, providing strong mutual authentication without transmitting reusable credentials.
- Requires PKI infrastructure for client and server certs
- Considered the strongest EAP method against credential theft
- Contrast: PEAP typically only requires a server-side certificate
Memory trick: TLS means Two-sided (mutual) Lock-Step certificates.