CWNA-109 · Question #27
You are managing a wireless access point in autonomous mode using the Web based interface. You capture traffic during this management task and notice that you can see the HTML code of the Web pages…
The correct answer is D. HTTP is in use instead of HTTPS. The error in administration that could be the cause of this security concern is that HTTP is in use instead of HTTPS. HTTP is an unencrypted protocol that transfers data in plain text over the network. This means that anyone who captures the traffic can see the HTML code of the…
Question
You are managing a wireless access point in autonomous mode using the Web based interface. You capture traffic during this management task and notice that you can see the HTML code of the Web pages used for access point management. What error in administration could be the cause of this security concern?
Options
- AIPsec is not in use of the management connection as recommended
- BA VPN with the AP is not established
- CWPA2 is disabled on the WLAN
- DHTTP is in use instead of HTTPS
How the community answered
(40 responses)- A5% (2)
- B3% (1)
- D93% (37)
Explanation
The error in administration that could be the cause of this security concern is that HTTP is in use instead of HTTPS. HTTP is an unencrypted protocol that transfers data in plain text over the network. This means that anyone who captures the traffic can see the HTML code of the Web pages used for access point management, as well as any sensitive information such as passwords or configuration settings. HTTPS is an encrypted protocol that uses SSL/TLS to secure the data transmission between the Web browser and the Web server. HTTPS prevents anyone from snooping on or tampering with the Web traffic. Therefore, HTTPS should always be used for Web based management of wireless access points, especially in autonomous mode where there is no centralized controller to enforce security policies.
Topics
Community Discussion
No community discussion yet for this question.