nerdexam
EC-Council

312-50V12 · Question #205

As the lead security engineer for a retail corporation, you are assessing the security of the wireless networks in the company's stores. One of your main concerns is the potential for "Wardriving"…

The correct answer is D. Implement WPA3 encryption for the store's Wi-Fi network. Implementing WPA3 encryption is the most suitable measure to mitigate wardriving risks by significantly strengthening wireless network security against exploitation without hindering customer access.

Submitted by marco_it· Mar 4, 2026Wireless Network, Mobile, IoT, and OT Hacking

Question

As the lead security engineer for a retail corporation, you are assessing the security of the wireless networks in the company's stores. One of your main concerns is the potential for "Wardriving" attacks, where attackers drive around with a Wi-Fi-enabled device to discover vulnerable wireless networks. Given the nature of the retail stores, you need to ensure that any security measures you implement do not interfere with customer experience, such as their ability to access in-store Wi-Fi. Taking into consideration these factors, which of the following would be the most suitable measure to mitigate the risk of Wardriving attacks?

Options

  • ALimit the range of the store's wireless signals
  • BImplement MAC address filtering
  • CDisable SSID broadcasting
  • DImplement WPA3 encryption for the store's Wi-Fi network

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    11% (4)
  • C
    3% (1)
  • D
    84% (31)

Why each option

Implementing WPA3 encryption is the most suitable measure to mitigate wardriving risks by significantly strengthening wireless network security against exploitation without hindering customer access.

ALimit the range of the store's wireless signals

Limiting signal range primarily makes discovery from a distance harder but does not prevent discovery from closer proximity or enhance the security of the network against exploitation once discovered.

BImplement MAC address filtering

MAC address filtering is easily circumvented by MAC spoofing and is impractical for a customer-facing Wi-Fi network that requires frequent connections from various devices.

CDisable SSID broadcasting

Disabling SSID broadcasting offers minimal security as the SSID can still be discovered by common tools and makes it more difficult for legitimate customers to connect, degrading user experience.

DImplement WPA3 encryption for the store's Wi-Fi networkCorrect

WPA3 encryption significantly enhances the security of the Wi-Fi network by providing stronger authentication and encryption protocols, such as Simultaneous Authentication of Equals (SAE), which makes it substantially more difficult for attackers to compromise the network through brute-force or offline dictionary attacks, even if the network is discovered via wardriving. This measure directly mitigates the vulnerability aspect of wardriving without negatively impacting the customer's ability to access the in-store Wi-Fi.

Concept tested: Wireless Network Security, WPA3 Encryption, Wardriving Mitigation

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/wpa3-security

Topics

#wireless security#Wardriving#WPA3#network security

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice