exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 586 discussion

Actual exam question from CompTIA's SY0-501
Question #: 586
Topic #: 1
[All SY0-501 Questions]

A security administrator is performing a risk assessment on a legacy WAP with a WEP-enabled wireless infrastructure. Which of the following should be implemented to harden the infrastructure without upgrading the WAP?

  • A. Implement WPA and TKIP
  • B. Implement WPS and an eight-digit pin
  • C. Implement WEP and RC4
  • D. Implement WPA2 Enterprise
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Jenkins3mol
Highly Voted 5 years, 6 months ago
excuse me...I would choose TKIP
upvoted 26 times
so
5 years, 5 months ago
explain.....
upvoted 2 times
renad_r
5 years, 5 months ago
because the question states that it's a legacy WAP, how can it be legacy and able to be configured to use WPA2-Enterprise? which is the strongest form of wireless authentication yet.
upvoted 15 times
SmackedWookiee
4 years ago
Because WAP2-Enterprise has been available for 17 years.
upvoted 1 times
kastanov
3 years, 12 months ago
It says without upgrading
upvoted 2 times
...
...
...
...
...
Leona001
Highly Voted 5 years, 3 months ago
Real answer is A. Read the question again, it states "without upgrading WAP".
upvoted 18 times
...
Brittle
Most Recent 3 years, 10 months ago
A I think makes sense
upvoted 1 times
...
Dion79
3 years, 11 months ago
Great Cheat Sheet for WiFi protocols on the address below answer will make sense then. https://searchnetworking.techtarget.com/feature/Wireless-encryption-basics-Understanding-WEP-WPA-and-WPA2
upvoted 1 times
Dion79
3 years, 11 months ago
"The numerous flaws in WEP revealed the urgent need for an alternative, but the deliberately slow and careful processes required to write a new security specification posed a conflict. In response, in 2003, Wi-Fi Alliance released WPA as an interim standard, while IEEE worked to develop a more advanced, long-term replacement for WEP."
upvoted 2 times
...
...
troxel
4 years ago
"To add support for WPA or WPA2, some old Wi-Fi access points might need to be replaced or have their firmware upgraded" https://en.wikipedia.org/wiki/Wired_Equivalent_Privacy#Weak_security Bad question Comptia
upvoted 2 times
...
SmackedWookiee
4 years ago
The answer is correct. TKIP is no longer recommended. WPS isn't secure and can be cracked in a matter of seconds. WEP and RC4 are both no longer secure. That leaves WPA2-Enterprise which has been around for 17 years.
upvoted 1 times
...
mdsabbir
4 years, 1 month ago
Legacy device does not support WPA2. How to verify WPA2 Compatibility Most Wi-Fi products bought in 2005 or after should support WPA2. If you have a wireless router, access points, computers, or other Wi-Fi devices that were purchased in 2005 or before, you might want to double-check the support of WPA2. The original security standard was Wired Equivalent Privacy (WEP). It was replaced by the original Wi-Fi Protected Access (WPA) in 2003 as an interim solution to the limited protection offered by WEP. The WPA program added support for Temporal Key Integrity Protocol (TKIP) encryption, an older form of security technology with some vulnerability to cryptographic attacks. WPA was replaced in 2004 with more advanced protocols of WPA2. So the answer is : WPA & TKIP
upvoted 3 times
...
KJ44
4 years, 1 month ago
I think the "legacy" part is just there to throw you off. WAP or Wireless Access Points are mainly about speed and range. The security protocols, such as WPA2 enterprise, should work with all of them.
upvoted 1 times
...
Banjo
4 years, 3 months ago
Great twist of a question. You do not need to upgrade the WAP (physical) in order to upgrade WPA (logical). D is the answer. I got it wrong, twice!
upvoted 5 times
...
certpro
4 years, 4 months ago
according to this article, given answer is correct : https://www.cisco.com/c/en/us/support/docs/smb/wireless/cisco-small-business-100-series-wireless-access-points/smb5163-configure-wireless-security-settings-on-a-wap.html Implementing WPA2 on "WAP" - (wireless access point)
upvoted 1 times
...
MichaelLangdon
4 years, 4 months ago
why are you the way you are CompTIA...I might just go for CISSP instead these questions are honestly ridiculous. just straight word salads 50 x more obscure then anything ive come across with Jason Dion, Mike Meyers, Messer, Certmaster, Gibson
upvoted 5 times
...
Hanzero
4 years, 7 months ago
A is the answer. You are not upgrading as the question states so it can't be D.
upvoted 3 times
...
jama
4 years, 8 months ago
the correct answer should be A, no way you can implement WPA2 enterprise without upgrade
upvoted 2 times
...
babati
4 years, 8 months ago
WPA2 is fully compliant with the 802.11i WLAN security standard. The only reason not to use WPA2 is if it is not supported by adapters, APs, or operating systems on the network. In many cases, devices will be compatible with a firmware or driver upgrade. The first version of Wi-Fi Protected Access (WPA) was designed to fix the security problems with WEP. Version 1 of WPA still uses the RC4 cipher but adds a mechanism called the Temporal Key Integrity Protocol (TKIP) to make it stronger.
upvoted 1 times
...
vaxakaw829
4 years, 8 months ago
A. Implement WPA and TKIP ... WPA2 is recommended unless you need to provide access to for legacy devices. All 802.11n devices support WPA2. ... TKIP is not permitted for 802.11n-based transmissions. It is only supported for legacy (802.11b, 802.11g and 802.11a) transmissions, which are limited to a maximum of 54 Mbps. ... If you need to accommodate legacy devices with an SSID, enable WPA encryption with the TKIP cipher. Keep in mind that this has an effect on performance. The additional AES cipher takes more computing power to run than simple TKIP does, therefore older, smaller devices may not support it. ... (https://www.juniper.net/documentation/en_US/junos-space-apps/network-director3.1/topics/concept/wireless-encryption-and-ciphers.html) WPA uses Temporal Key Integrity Protocol (TKIP) for generating encryption keys. ... TKIP, combined with an improved implementation of the same RC4 stream cipher that WEP uses, provides WPA encryption. TKIP enables backward-compatibility with legacy WEP, uses 128-bit keys, and uses a 48-bit initialization vector. (Mike Meyers’ CompTIA Security+ p. 328-329)
upvoted 1 times
...
Diogenes_td
4 years, 9 months ago
WPA2-TKIP would be the best option. Since it's not available, then WPA-TKIP. WPA2-Enterprise / WPA2 802.1x has hardware restrictions on modules prior to 2005. Unless I'm missing something...
upvoted 1 times
Diogenes_td
4 years, 9 months ago
Sorry, «D» can still be right if you can make WPA2 - Enterprise work with TKIP;
upvoted 1 times
...
Diogenes_td
4 years, 9 months ago
Nope, I was right the first time: https://www.comparitech.com/blog/information-security/wpa2-aes-tkip/ WPA2 - Personal can use TKIP. WPA2 - Enterprise cannot.
upvoted 1 times
...
...
aymenfarah
4 years, 9 months ago
without upgrading the WAP? i think C
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago