For EAP-MSCHAPv2 client authentication via RADIUS, which EAP outer method should ISE be configured to use?
Choose an answer
Tap an option to check your answer.
Correct answer: PEAP.
Why this is the answer
PEAP (Protected Extensible Authentication Protocol) is the correct EAP outer method because it establishes a TLS tunnel to protect the inner EAP method, such as EAP-MSCHAPv2. EAP-MSCHAPv2 itself does not provide robust protection against eavesdropping or credential theft, so it needs to be encapsulated within a secure tunnel like the one provided by PEAP. LDAP is a directory service protocol, not an EAP method. EAP-FAST (Flexible Authentication via Secure Tunneling) is an EAP method that uses PACs (Protected Access Credentials) for mutual authentication and tunnel establishment, but it's not typically used to encapsulate EAP-MSCHAPv2. EAP-TLS (Transport Layer Security) is a strong certificate-based EAP method that doesn't require an outer tunnel for protection, as it uses TLS directly for authentication and key exchange.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed