CWNP
CWSP-206 · Question #120
As the primary security engineer for a large corporate network, you have been asked to author a new security policy for the wireless network. While most client devices support 802.1X authentication…
The correct answer is C. Static passwords should be changed on a regular basis to minimize the vulnerabilities of a PSK-. See the full explanation below for the reasoning.
Question
As the primary security engineer for a large corporate network, you have been asked to author a new security policy for the wireless network. While most client devices support 802.1X authentication, some legacy devices still only support passphrase/PSK-based security methods. When writing the 802.11 security policy, what password-related items should be addressed?
Options
- ACertificates should always be recommended instead of passwords for 802.11 client authentication.
- BPassword complexity should be maximized so that weak WEP IV attacks are prevented.
- CStatic passwords should be changed on a regular basis to minimize the vulnerabilities of a PSK-
- DEAP-TLS must be implemented in such scenarios.
- EMS-CHAPv2 passwords used with EAP/PEAPv0 should be stronger than typical WPA2-PSK
How the community answered
(20 responses)- A5% (1)
- B15% (3)
- C75% (15)
- D5% (1)
Community Discussion
No community discussion yet for this question.