ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
An organization is deploying a new WPA2-Enterprise Wi-Fi network that must provide the strongest possible mutual authentication while preventing offline password-cracking attacks. All corporate laptops can be provisioned with individual user and device certificates issued by the firm's internal PKI. Which Extensible Authentication Protocol (EAP) method should the security administrator configure on the RADIUS server to best satisfy these requirements?
EAP-TLS uses X.509 certificates on both the supplicant and the authentication server, creating a mutually authenticated TLS tunnel before any user credentials are exchanged. Because authentication relies on asymmetric keys stored in the certificates, no password-based challenge is exposed, eliminating the possibility of offline password-cracking attacks. PEAP and EAP-FAST rely on tunneled password methods and only require a server certificate, providing less assurance. EAP-MD5 offers only one-way authentication and transmits a hash that is vulnerable to dictionary attacks, making it unsuitable for secure wireless deployments.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is EAP-TLS and how does it work?
Open an interactive chat with Bash
What is a PKI, and how does it relate to EAP-TLS?
Open an interactive chat with Bash
Why is EAP-TLS more secure than other EAP methods like PEAP or EAP-FAST?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Network and Communication Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .