nerdexam
CompTIA

N10-005 · Question #803

Many of the corporate users work from a coffee shop during their lunch breaks. The coffee shop only has an open wireless network. Which of the following should the administrator recommend to users…

The correct answer is B. Use a VPN after connecting to the coffee shop wireless. On an open (unencrypted) public wireless network, a VPN is the only reliable way to protect all traffic in transit by creating an encrypted tunnel from the laptop to a trusted endpoint. No client-side wireless setting can add encryption when the AP itself is open.

Network security

Question

Many of the corporate users work from a coffee shop during their lunch breaks. The coffee shop only has an open wireless network. Which of the following should the administrator recommend to users to secure their wireless communications at the coffee shop?

Options

  • AEnable the host-based firewall on each of the laptops
  • BUse a VPN after connecting to the coffee shop wireless
  • CEdit the SSID connection information and change 'open' to 'shared'
  • DConnect to the open SSID then switch on WPA2 encryption

How the community answered

(56 responses)
  • A
    4% (2)
  • B
    89% (50)
  • C
    5% (3)
  • D
    2% (1)

Why each option

On an open (unencrypted) public wireless network, a VPN is the only reliable way to protect all traffic in transit by creating an encrypted tunnel from the laptop to a trusted endpoint. No client-side wireless setting can add encryption when the AP itself is open.

AEnable the host-based firewall on each of the laptops

A host-based firewall controls inbound and outbound connection attempts but does not encrypt network traffic, leaving data visible to any sniffer on the open wireless network.

BUse a VPN after connecting to the coffee shop wirelessCorrect

A VPN encrypts all outbound traffic from the user's device before it traverses the open wireless network, preventing eavesdropping, packet sniffing, and man-in-the-middle attacks at the coffee shop. The encrypted tunnel terminates at a corporate or trusted VPN gateway, ensuring data confidentiality and integrity regardless of the underlying network's security posture.

CEdit the SSID connection information and change 'open' to 'shared'

The SSID is simply a network name identifier; changing a client's saved SSID profile label from 'open' to 'shared' has no effect on the encryption or authentication method used by the access point.

DConnect to the open SSID then switch on WPA2 encryption

WPA2 encryption is enforced at the access point level; a wireless client cannot unilaterally enable WPA2 encryption if the AP is configured as an open network.

Concept tested: VPN for securing communications on open wireless networks

Source: https://learn.microsoft.com/en-us/windows/security/operating-system-security/network-security/vpn/vpn-guide

Topics

#VPN#open wireless#public hotspot#wireless security

Community Discussion

No community discussion yet for this question.

Full N10-005 Practice