You plan to deploy 802.1X authentication for wired access using NPS. You do not want to deploy client certificates and you require users to authenticate with their AD credentials while protecting the authentication inside a TLS tunnel. What should you configure on the NPS?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure PEAP with EAP-MSCHAPv2 and install a server certificate (with Server Authentication EKU) on the NPS that is trusted by clients..
Why this is the answer
This option is correct because PEAP (Protected Extensible Authentication Protocol) with EAP-MSCHAPv2 allows users to authenticate with their Active Directory credentials, fulfilling the requirement for user authentication. The server certificate on the NPS server creates a TLS tunnel, protecting the authentication process, and clients only need to trust this server certificate, avoiding the need for client certificates. EAP-TLS is incorrect because it requires client certificates, which the scenario explicitly states should not be deployed. PEAP-TLS is not a standard EAP method; PEAP typically encapsulates other EAP methods like EAP-MSCHAPv2 or EAP-TLS. EAP-MD5 is incorrect because it is considered insecure and does not provide a protected (TLS) tunnel for password authentication.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed