CompTIA Network+ (N10-009)Network SecurityHard

A security engineer is configuring 802.1X for a corporate wireless network and wants both the client and the authentication server to mutually verify each other using digital certificates, eliminating the risk of credential theft via a fake authentication portal. Which EAP method should be selected?

  1. AEAP-MD5
  2. BLEAP
  3. CPEAP
  4. DEAP-TLS
Show answer & explanation

Correct answer: D. EAP-TLS

EAP-TLS requires certificates on both the client and server, providing mutual authentication and eliminating password-based credential theft, unlike PEAP (which typically only authenticates the server via certificate while clients use credentials), EAP-MD5 (weak, no mutual auth, vulnerable to offline attacks), and LEAP (deprecated Cisco proprietary method with known weaknesses).

Why the other options are wrong

  • A. EAP-MD5 offers one-way, weak hash-based authentication with no mutual certificate verification.
  • B. LEAP is a deprecated, vulnerable proprietary EAP method.
  • C. PEAP typically authenticates only the server via certificate, client uses credentials inside the tunnel.

EAP-TLS

An 802.1X EAP method requiring digital certificates on both the client and authentication server, providing strong mutual authentication without transmitting reusable credentials.

  • Requires PKI infrastructure for client and server certs
  • Considered the strongest EAP method against credential theft
  • Contrast: PEAP typically only requires a server-side certificate

Memory trick: TLS means Two-sided (mutual) Lock-Step certificates.

More Network Security questions