GSLC · Question #525
A Web developer with your company wants to have wireless access for contractors that come in to work on various projects. The process of getting this approved takes time. So rather than wait, he has…
The correct answer is B. An unauthorized WAP is one way for hackers to get into a network. A rogue wireless access point installed without IT authorization creates an unmonitored entry point into the internal network, bypassing all perimeter security controls.
Question
A Web developer with your company wants to have wireless access for contractors that come in to work on various projects. The process of getting this approved takes time. So rather than wait, he has put his own wireless router attached to one of the network ports in his department. What security risk does this present?
Options
- AIt is likely to increase network traffic and slow down network performance.
- BAn unauthorized WAP is one way for hackers to get into a network.
- CNone, adding a wireless access point is a common task and not a security risk.
- DThis circumvents network intrusion detection.
How the community answered
(37 responses)- A3% (1)
- B86% (32)
- C8% (3)
- D3% (1)
Why each option
A rogue wireless access point installed without IT authorization creates an unmonitored entry point into the internal network, bypassing all perimeter security controls.
Performance degradation is a minor operational concern, not the primary security risk - the critical issue is the unauthorized and uncontrolled network access the rogue WAP creates.
An unauthorized WAP (rogue access point) connects directly to the internal network segment without going through firewalls, NAC systems, or IDS/IPS monitoring. Any attacker within wireless range can connect to it and gain unauthenticated access to internal resources, effectively bypassing all perimeter defenses. This is a well-documented physical and network security threat classified as a rogue access point attack.
Adding any network device without authorization is a security risk because it circumvents change management, security reviews, and monitoring processes that protect the network.
While a rogue WAP may not be monitored by IDS, this is a secondary concern - the fundamental risk is that it provides attackers direct unauthenticated access to the internal network.
Concept tested: Rogue access point physical and network security risk
Source: https://www.cisecurity.org/controls/wireless-access-control
Topics
Community Discussion
No community discussion yet for this question.