GPEN · Question #368
You are concerned about attackers simply passing by your office, discovering your wireless network, and getting into your network via the wireless connection. Which of the following are NOT steps in s
The correct answer is C. Strong password policies on workstations. E. Hardening the server OS. Strong workstation password policies and server OS hardening are general security controls that do not directly secure the wireless network connection, making them the two answers that are NOT wireless-specific security steps.
Question
You are concerned about attackers simply passing by your office, discovering your wireless network, and getting into your network via the wireless connection. Which of the following are NOT steps in securing your wireless connection? Each correct answer represents a complete solution. Choose two.
Options
- ANot broadcasting SSID
- BMAC filtering on the router
- CStrong password policies on workstations.
- DUsing either WEP or WPA encryption
- EHardening the server OS
How the community answered
(24 responses)- A4% (1)
- B8% (2)
- C75% (18)
- D13% (3)
Why each option
Strong workstation password policies and server OS hardening are general security controls that do not directly secure the wireless network connection, making them the two answers that are NOT wireless-specific security steps.
Disabling SSID broadcast is a wireless-specific security measure that reduces network visibility to passive scanners, making it a valid - if limited - step in wireless security hardening.
MAC address filtering on the router is a direct wireless access control that restricts which devices can associate with the wireless network based on their hardware MAC address.
Strong password policies on workstations are an endpoint access control measure that applies to any network type and does not address how wireless traffic is protected, who can join the wireless network, or how the wireless channel itself is secured.
Using WEP or WPA encryption directly protects the confidentiality and integrity of data transmitted over the wireless channel, making it a fundamental wireless network security control.
Hardening the server OS is a server-side security practice aimed at reducing the attack surface of the server itself, but it does not control wireless network access, encrypt wireless transmissions, or prevent unauthorized devices from associating with the wireless access point.
Concept tested: Identifying wireless-specific versus general security controls
Source: https://www.cisa.gov/news-events/news/securing-wireless-networks
Topics
Community Discussion
No community discussion yet for this question.