nerdexam
Huawei

H12-311_V3.0 · Question #238

In the wireless access control scenario, which of the following methods is recommended to distinguish between internal employees and external visitors?

The correct answer is C. Set up different SSIDs for employees and guests. Setting up separate SSIDs for employees and guests (C) is the recommended approach because it creates distinct network segments with different security policies, access rights, and authentication methods - employees get secured corporate access while guests are isolated on a…

WLAN Security Technologies

Question

In the wireless access control scenario, which of the following methods is recommended to distinguish between internal employees and external visitors?

Options

  • ADistinguish according to different user names
  • BAccording to whether the MAC address of the wireless terminal is registered or not
  • CSet up different SSIDs for employees and guests
  • DAccording to the type of wireless terminal

How the community answered

(47 responses)
  • A
    2% (1)
  • B
    11% (5)
  • C
    83% (39)
  • D
    4% (2)

Explanation

Setting up separate SSIDs for employees and guests (C) is the recommended approach because it creates distinct network segments with different security policies, access rights, and authentication methods - employees get secured corporate access while guests are isolated on a separate network with limited permissions. This is a standard enterprise wireless design pattern built into virtually all modern access points and controllers.

Why the distractors fail:

  • A (username-based) - Usernames can be shared, guessed, or misused; they don't inherently segment the network or enforce different policies at the infrastructure level.
  • B (MAC address registration) - MAC addresses are trivially spoofed and change frequently (especially with modern MAC randomization on smartphones), making this unreliable for access control.
  • D (terminal type) - Device type (phone, laptop, etc.) has no bearing on whether someone is an employee or visitor, and cannot be enforced as a reliable control.

Memory tip: Think "SSID = Segment ID" - different SSIDs map to different VLANs and policies, so the network itself enforces the boundary rather than relying on soft identifiers like usernames or MAC addresses that can be faked or shared.

Topics

#SSID configuration#Guest access control#Network isolation#Access authentication

Community Discussion

No community discussion yet for this question.

Full H12-311_V3.0 Practice