A PKI-mature campus already issues managed device certificates and wants the strongest common enterprise WLAN EAP choice among TLS, TTLS, and PEAP. Which selection best fits?
Select an answer to reveal the explanation.
Short Explanation
If the campus already runs a grown-up PKI, EAP-TLS puts those device certs to work for mutual auth. Throwing that away for open Wi-Fi, password-only PEAP forever, or WEP wastes the investment.
Full Explanation
On a PKI-mature campus with client certificates available, EAP-TLS is typically preferred because it provides mutual certificate authentication and avoids password-based inner methods. EAP-TTLS and PEAP remain valid when client certs are impractical, but they are not the strongest fit when a working device PKI already exists. Open auth and WEP are not appropriate enterprise answers.