220-1002 · Question #653
220-1002 Question #653: Real Exam Question with Answer & Explanation
The correct answer is B: Enabling WPA2-Enterprise encryption. The stated answer (B: WPA2-Enterprise, F: Disable SSID broadcast) appears to be an error in the answer key. The BEST defenses against a home router being recruited into a botnet are C) Changing default credentials - botnets (like Mirai) specifically scan for routers using factory
Question
Options
- AUpgrading to an enterprise-grade router
- BEnabling WPA2-Enterprise encryption
- CChanging the default credentials
- DUpdating to the latest firmware
- EReducing the transmit power levels
- FDisabling the SSID from being broadcast
Explanation
The stated answer (B: WPA2-Enterprise, F: Disable SSID broadcast) appears to be an error in the answer key. The BEST defenses against a home router being recruited into a botnet are C) Changing default credentials - botnets (like Mirai) specifically scan for routers using factory-default usernames and passwords to hijack them - and D) Updating to the latest firmware - firmware patches close known vulnerabilities that malware exploits. WPA2-Enterprise (B) requires a RADIUS server, is impractical in a SOHO environment, and only governs Wi-Fi client authentication, not the router's management interface. Disabling SSID broadcast (F) is security through obscurity and provides no real protection against botnet scanning tools that detect networks regardless of broadcast status. C and D are the industry-standard correct answers for this scenario.
Community Discussion
No community discussion yet for this question.