nerdexam
CompTIA

CAS-001 · Question #40

An organization recently upgraded its wireless infrastructure to support WPA2 and requires all clients to use this method. After the upgrade, several critical wireless clients fail to connect…

The correct answer is B. Create a separate SSID and WEP key on a new network segment and only allow required communication. Creating a separate SSID and WEP key on a new, isolated network segment with only required communication allowed (B) is the most secure option. WEP is a broken encryption protocol, so the goal is to contain the risk. Network segmentation isolates the vulnerable legacy clients…

Technical Integration of Enterprise Components

Question

An organization recently upgraded its wireless infrastructure to support WPA2 and requires all clients to use this method. After the upgrade, several critical wireless clients fail to connect because they are only WEP compliant. For the foreseeable future, none of the affected clients have an upgrade path to put them into compliance with the WPA2 requirement. Which of the following provides the MOST secure method of integrating the non-compliant clients into the network?

Options

  • ACreate a separate SSID and WEP key to support the legacy clients and enable detection of rogue APs.
  • BCreate a separate SSID and WEP key on a new network segment and only allow required communication
  • CCreate a separate SSID and require the legacy clients to connect to the wireless network using certificate-
  • DCreate a separate SSID and require the use of dynamic WEP keys.

How the community answered

(45 responses)
  • A
    9% (4)
  • B
    71% (32)
  • C
    4% (2)
  • D
    16% (7)

Explanation

Creating a separate SSID and WEP key on a new, isolated network segment with only required communication allowed (B) is the most secure option. WEP is a broken encryption protocol, so the goal is to contain the risk. Network segmentation isolates the vulnerable legacy clients from the main corporate network, limiting the blast radius if WEP is cracked. Restricting communication to only what is required applies the principle of least privilege, further reducing exposure. Option A also creates a separate SSID but adds rogue AP detection without segmenting the network, providing less containment. Option D (dynamic WEP keys) improves WEP slightly but does not segment the network. Option C is incomplete as written but would still involve WEP with certificates - also without proper segmentation. Segmentation combined with restricted communication is the strongest compensating control available.

Topics

#WPA2#WEP legacy clients#wireless security#network segmentation

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice