Which method should be used to meet the requirements?

A customer wants FSR and certificate-based authentication. The solution must be simple to deploy. Which method should be used to meet the requirements?
A. EAP-TLS
B. PEAP-MSCHAPv2
C. EAP-FAST
D. PEAP-MSCHAPv2 machine authentication

cisco-exams

2 thoughts on “Which method should be used to meet the requirements?

  1. C may be incorrect, B can be correct

    A – hard to implement
    B – could be, uses CERTIFICATE on server side
    C – EAP-FAST do not use CERTIFICATES, it uses PAC keys. Server side certificate is OPTIONAL
    D – PEAP-MSCHAPv2 machine authentication – ??? machine means client side? If yes, client side also do not use certificates

    1. EAP-FAST: EAP-Chaining will do the thing with EAP-TLS as inner auth method… But I don’t think it’s simpler than EAP-TLS on it’s own.
      Ambiguous question.

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.