nerdexam
CWNP

CWSP-207 · Question #8

As the primary security engineer for a large corporate network, you have been asked to author a new security policy for the wireless network. While most client devices support 802.1X authentication…

The correct answer is C. Static passwords should be changed on a regular basis to minimize the vulnerabilities of a PSK-. See the full explanation below for the reasoning.

Question

As the primary security engineer for a large corporate network, you have been asked to author a new security policy for the wireless network. While most client devices support 802.1X authentication, some legacy devices still only support passphrase/PSK-based security methods. When writing the 802.11 security policy, what password-related items should be addressed?

Options

  • AMSCHAPv2 passwords used with EAP/PEAPv0 should be stronger than typical WPA2-PSK
  • BPassword complexity should be maximized so that weak WEP IV attacks are prevented.
  • CStatic passwords should be changed on a regular basis to minimize the vulnerabilities of a PSK-
  • DCertificates should always be recommended instead of passwords for 802.11 client authentication.
  • EEAP-TLS must be implemented in such scenarios.

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    73% (27)
  • D
    8% (3)
  • E
    14% (5)

Community Discussion

No community discussion yet for this question.

Full CWSP-207 Practice