nerdexam
CompTIA

CAS-002 · Question #717

An organization recently upgraded its wireless infrastructure to support WPA2 and requires all clients to use this method. After the upgrade, several critical wireless clients fail to connect…

The correct answer is B. Create a separate SSID and WEP key on a new network segment and only allow required. When WEP-only clients cannot be upgraded, the most secure option is to isolate them on a dedicated SSID attached to a separate network segment and restrict permitted traffic to only what those clients require.

Technical Integration of Enterprise Components

Question

An organization recently upgraded its wireless infrastructure to support WPA2 and requires all clients to use this method. After the upgrade, several critical wireless clients fail to connect because they are only WEP compliant. For the foreseeable future, none of the affected clients have an upgrade path to put them into compliance with the WPA2 requirement. Which of the following provides the MOST secure method of integrating the non-compliant clients into the network?

Options

  • ACreate a separate SSID and WEP key to support the legacy clients and enable detection
  • BCreate a separate SSID and WEP key on a new network segment and only allow required
  • CCreate a separate SSID and require the legacy clients to connect to the wireless network
  • DCreate a separate SSID and require the use of dynamic WEP keys.

How the community answered

(32 responses)
  • A
    16% (5)
  • B
    72% (23)
  • C
    6% (2)
  • D
    6% (2)

Why each option

When WEP-only clients cannot be upgraded, the most secure option is to isolate them on a dedicated SSID attached to a separate network segment and restrict permitted traffic to only what those clients require.

ACreate a separate SSID and WEP key to support the legacy clients and enable detection

Enabling detection alongside a WEP SSID adds monitoring but without network segmentation the legacy clients remain on the same segment as other resources, allowing a WEP compromise to affect the broader network.

BCreate a separate SSID and WEP key on a new network segment and only allow requiredCorrect

Placing legacy WEP clients on their own SSID and a separate network segment uses infrastructure-level segmentation to contain the inherent cryptographic weaknesses of WEP. Restricting permitted traffic to only required flows limits lateral movement and blast radius if the WEP key is recovered by an attacker. This ensures that a WEP compromise cannot propagate to the WPA2 network or its resources.

CCreate a separate SSID and require the legacy clients to connect to the wireless network

Creating a separate SSID without enforcing a distinct network segment at the infrastructure level does not prevent a compromised WEP client from reaching resources accessible to WPA2 clients.

DCreate a separate SSID and require the use of dynamic WEP keys.

Dynamic WEP uses 802.1X to rotate keys more frequently and reduces key-reuse attacks, but it does not fix WEP's fundamental RC4 cipher weaknesses or its weak initialization vector design, making it far less secure than genuine network segmentation.

Concept tested: Network segmentation to isolate legacy WEP wireless clients

Source: https://csrc.nist.gov/publications/detail/sp/800-97/final

Topics

#WEP legacy#WPA2#wireless segmentation#network security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice