Protected Extensible Authentication Protocol (PEAP)
An EAP method that builds a TLS tunnel authenticated by the server's certificate, then runs a second, password-based EAP method inside it to authenticate the user.
Protected EAP is one of the authentication methods carried by the Extensible Authentication Protocol, commonly used in enterprise wireless networks with IEEE 802.1X. It runs in two phases. First the client and the authentication server set up a TLS tunnel in which commonly only the server proves its identity, with a certificate. Then a second EAP method runs inside that tunnel to authenticate the user, commonly a username and password exchange such as MS-CHAPv2. PEAP was published as a series of IETF Internet-Drafts and vendor specifications rather than as a standards-track RFC.
The comparison candidates are expected to make is with EAP-TLS, which requires a certificate on the client as well as the server. PEAP does not require client certificates, which eases deployment but relies on passwords. Its security depends heavily on the client checking the server’s certificate. If clients accept any certificate, an attacker running an evil twin or rogue access point can terminate the tunnel, collect the inner exchange and attempt to crack the password offline. Correct configuration sets the expected certificate authority and server name on every client.
Exam relevance: a scenario asking for enterprise wireless authentication without client certificates is likely to point to PEAP, while one requiring mutual certificate-based authentication points to EAP-TLS. Candidates are expected to link PEAP’s main weakness to clients that skip server certificate validation.