nerdexam
GIAC

GSLC · Question #274

You are concerned about attackers simply passing by your office, discovering your wireless network, and getting into your network via the wireless connection. Which of the following are NOT steps in s

The correct answer is B. Hardening the server OS E. Strong password policies on workstations.. Wireless-specific security steps target the radio link and access control; hardening the server OS and enforcing workstation password policies are general security practices unrelated to wireless access protection.

Security Architecture & Engineering

Question

You are concerned about attackers simply passing by your office, discovering your wireless network, and getting into your network via the wireless connection. Which of the following are NOT steps in securing your wireless connection? Each correct answer represents a complete solution. Choose two.

Options

  • AUsing either WEP or WPA encryption
  • BHardening the server OS
  • CMAC filtering on the router
  • DNot broadcasting SSID
  • EStrong password policies on workstations.

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    79% (31)
  • C
    13% (5)
  • D
    3% (1)

Why each option

Wireless-specific security steps target the radio link and access control; hardening the server OS and enforcing workstation password policies are general security practices unrelated to wireless access protection.

AUsing either WEP or WPA encryption

WEP or WPA encryption directly secures wireless transmissions, making it a valid and direct step in protecting the wireless link from eavesdropping and unauthorized access.

BHardening the server OSCorrect

Hardening the server OS is a general server security practice that addresses vulnerabilities in the operating system and does not directly prevent unauthorized discovery or connection to a wireless network.

CMAC filtering on the router

MAC filtering on the router restricts which hardware devices can associate with the wireless network, making it a direct wireless-layer access control measure.

DNot broadcasting SSID

Disabling SSID broadcasting suppresses the network name from beacon frames, reducing the network's visibility to casual wardriving or passersby.

EStrong password policies on workstations.Correct

Strong password policies on workstations are a general endpoint access control and do not stop an attacker who is attempting to connect to the wireless network itself before any workstation authentication occurs.

Concept tested: Wireless network security controls identification

Source: https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/116234-technote-wlan-security-00.html

Topics

#wireless security#WEP/WPA#SSID broadcasting#MAC filtering

Community Discussion

No community discussion yet for this question.

Full GSLC Practice