N10-005 · Question #803
Many of the corporate users work from a coffee shop during their lunch breaks. The coffee shop only has an open wireless network. Which of the following should the administrator recommend to users…
The correct answer is B. Use a VPN after connecting to the coffee shop wireless. On an open (unencrypted) public wireless network, a VPN is the only reliable way to protect all traffic in transit by creating an encrypted tunnel from the laptop to a trusted endpoint. No client-side wireless setting can add encryption when the AP itself is open.
Question
Many of the corporate users work from a coffee shop during their lunch breaks. The coffee shop only has an open wireless network. Which of the following should the administrator recommend to users to secure their wireless communications at the coffee shop?
Options
- AEnable the host-based firewall on each of the laptops
- BUse a VPN after connecting to the coffee shop wireless
- CEdit the SSID connection information and change 'open' to 'shared'
- DConnect to the open SSID then switch on WPA2 encryption
How the community answered
(56 responses)- A4% (2)
- B89% (50)
- C5% (3)
- D2% (1)
Why each option
On an open (unencrypted) public wireless network, a VPN is the only reliable way to protect all traffic in transit by creating an encrypted tunnel from the laptop to a trusted endpoint. No client-side wireless setting can add encryption when the AP itself is open.
A host-based firewall controls inbound and outbound connection attempts but does not encrypt network traffic, leaving data visible to any sniffer on the open wireless network.
A VPN encrypts all outbound traffic from the user's device before it traverses the open wireless network, preventing eavesdropping, packet sniffing, and man-in-the-middle attacks at the coffee shop. The encrypted tunnel terminates at a corporate or trusted VPN gateway, ensuring data confidentiality and integrity regardless of the underlying network's security posture.
The SSID is simply a network name identifier; changing a client's saved SSID profile label from 'open' to 'shared' has no effect on the encryption or authentication method used by the access point.
WPA2 encryption is enforced at the access point level; a wireless client cannot unilaterally enable WPA2 encryption if the AP is configured as an open network.
Concept tested: VPN for securing communications on open wireless networks
Source: https://learn.microsoft.com/en-us/windows/security/operating-system-security/network-security/vpn/vpn-guide
Topics
Community Discussion
No community discussion yet for this question.