CAS-002 · Question #717
An organization recently upgraded its wireless infrastructure to support WPA2 and requires all clients to use this method. After the upgrade, several critical wireless clients fail to connect…
The correct answer is B. Create a separate SSID and WEP key on a new network segment and only allow required. When WEP-only clients cannot be upgraded, the most secure option is to isolate them on a dedicated SSID attached to a separate network segment and restrict permitted traffic to only what those clients require.
Question
An organization recently upgraded its wireless infrastructure to support WPA2 and requires all clients to use this method. After the upgrade, several critical wireless clients fail to connect because they are only WEP compliant. For the foreseeable future, none of the affected clients have an upgrade path to put them into compliance with the WPA2 requirement. Which of the following provides the MOST secure method of integrating the non-compliant clients into the network?
Options
- ACreate a separate SSID and WEP key to support the legacy clients and enable detection
- BCreate a separate SSID and WEP key on a new network segment and only allow required
- CCreate a separate SSID and require the legacy clients to connect to the wireless network
- DCreate a separate SSID and require the use of dynamic WEP keys.
How the community answered
(32 responses)- A16% (5)
- B72% (23)
- C6% (2)
- D6% (2)
Why each option
When WEP-only clients cannot be upgraded, the most secure option is to isolate them on a dedicated SSID attached to a separate network segment and restrict permitted traffic to only what those clients require.
Enabling detection alongside a WEP SSID adds monitoring but without network segmentation the legacy clients remain on the same segment as other resources, allowing a WEP compromise to affect the broader network.
Placing legacy WEP clients on their own SSID and a separate network segment uses infrastructure-level segmentation to contain the inherent cryptographic weaknesses of WEP. Restricting permitted traffic to only required flows limits lateral movement and blast radius if the WEP key is recovered by an attacker. This ensures that a WEP compromise cannot propagate to the WPA2 network or its resources.
Creating a separate SSID without enforcing a distinct network segment at the infrastructure level does not prevent a compromised WEP client from reaching resources accessible to WPA2 clients.
Dynamic WEP uses 802.1X to rotate keys more frequently and reduces key-reuse attacks, but it does not fix WEP's fundamental RC4 cipher weaknesses or its weak initialization vector design, making it far less secure than genuine network segmentation.
Concept tested: Network segmentation to isolate legacy WEP wireless clients
Source: https://csrc.nist.gov/publications/detail/sp/800-97/final
Topics
Community Discussion
No community discussion yet for this question.