QuestionQ90

Security Fundamentals

Question Image

Refer to the exhibit. Which two steps must an engineer take to provide the highest encryption and authentication by using domain credentials from LDAP?

Choose two
  • A Select PSK under Authentication Key Management.
  • B Select Static-WEP + 802.1X on Layer 2 Security.
  • C Select WPA+WPA2 on Layer 2 Security.
  • D Select 802.1X from under Authentication Key Management.
  • E Select WPA Policy with TKIP Encryption.
Explanation

For a WLAN that authenticates users against domain credentials held in LDAP with the strongest available encryption, the WLC's Layer 2 Security must be set to WPA+WPA2 (enabling the AES cipher shown in the WPA2 Encryption section) and 802.1X must be enabled under Authentication Key Management so client credentials are validated through an EAP exchange rather than a shared key. PSK and Static-WEP do not use per-user domain credentials, and plain WPA with TKIP is a weaker legacy option than the AES cipher available once WPA+WPA2 is selected.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!