220-1102 - Security (25% of the exam) - Section 2.2

Compare and contrast wireless security protocols and authentication methods.

Compare wireless security protocols and encryption - WiFi Protected Access 2 (WPA2) versus WPA3, and Temporal Key Integrity Protocol (TKIP) versus Advanced Encryption Standard (AES) - and choose the stronger option for a stated requirement. Contrast authentication methods including Remote Authentication Dial-In User Service (RADIUS), Terminal Access Controller Access-Control System (TACACS+), Kerberos, and multifactor authentication, and match each to the right access-control scenario.

WPA2WPA3AES vs TKIPRADIUSMultifactor

Practice question for this objective

Free sampleSecuritymedium

Which statement correctly compares TKIP and AES-CCMP as used in wireless security?

  • ATKIP is a block cipher that provides better message integrity than the weaker AES-CCMP cipher.
  • BTKIP is a legacy protocol retained for backward compatibility, while AES-CCMP is the stronger current standard. Correct
  • CAES and TKIP are interchangeable names for the same 128-bit wireless encryption algorithm.
  • DAES is deprecated under WPA3, which returns to TKIP for better performance on older client hardware.
TKIP is a legacy backward-compatibility cipher, while AES-CCMP is the stronger current encryption standard recommended for WPA2 and WPA3 networks. TKIP was designed to run on WEP-era hardware and carries the weaknesses of RC4, whereas AES-CCMP is a modern block cipher, so selecting AES rather than TKIP is the correct choice on current networks.

Why A is wrong: Tempting because both terms appear together in WPA2 settings, but TKIP is a key-mixing wrapper around RC4, and AES-CCMP is the stronger option, so this reverses their strengths.

Why B is correct: This states the accepted relationship: TKIP was a stopgap to patch WEP hardware, whereas AES-CCMP is the robust cipher recommended for modern networks.

Why C is wrong: Tempting because both are selectable ciphers in WPA2, but they are entirely different algorithms and are not interchangeable names for one thing.

Why D is wrong: Tempting because WPA3 does change the handshake, but it strengthens rather than abandons AES and does not revert to the discredited TKIP cipher.

See more 220-1102 practice questions, answers explained.

Exam traps in Security

Answers that look right on this material and are not. Each one is a distractor from a different question in the 220-1102 bank for this domain.

  • WPA2-Personal with a long pre-shared key that is rotated each quarter.

    Why it is wrong: A rotated strong key improves hygiene, but it is still one shared secret, so a single leaver cannot be revoked without changing it for everyone.

  • TKIP, a per-packet key mixing protocol built to extend the working life of legacy WEP hardware.

    Why it is wrong: Tempting because TKIP is permitted under WPA2 for backward compatibility, but it is the weaker fallback cipher, not the strongest protection WPA2 offers.

  • TKIP, because it was designed as the replacement for WEP and is the WPA2 default

    Why it is wrong: TKIP was a stopgap upgrade over WEP for original WPA and is now legacy and weak, so it does not meet a requirement for the strongest WPA2 encryption.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.