nerdexam
CompTIA

SY0-301 · Question #352

Joe, the systems administrator, is setting up a wireless network for his team's laptops only and needs to prevent other employees from accessing it. Which of the following would BEST address this?

The correct answer is D. Implement MAC filtering on the access point. To restrict wireless access to a specific group of devices, MAC address filtering is the most targeted and direct technical control. It allows the administrator to create an explicit allowlist of approved device hardware addresses.

Security architecture

Question

Joe, the systems administrator, is setting up a wireless network for his team's laptops only and needs to prevent other employees from accessing it. Which of the following would BEST address this?

Options

  • ADisable default SSID broadcasting.
  • BUse WPA instead of WEP encryption.
  • CLower the access point's power settings.
  • DImplement MAC filtering on the access point.

How the community answered

(40 responses)
  • B
    3% (1)
  • C
    3% (1)
  • D
    95% (38)

Why each option

To restrict wireless access to a specific group of devices, MAC address filtering is the most targeted and direct technical control. It allows the administrator to create an explicit allowlist of approved device hardware addresses.

ADisable default SSID broadcasting.

Disabling SSID broadcasting hides the network name but does not prevent unauthorized users who discover the SSID through passive scanning from connecting.

BUse WPA instead of WEP encryption.

Upgrading from WEP to WPA improves encryption strength but does not restrict which devices can attempt to authenticate and join the network.

CLower the access point's power settings.

Lowering transmit power reduces signal range but does not enforce access control - any device within the reduced range can still attempt to connect.

DImplement MAC filtering on the access point.Correct

MAC filtering on the access point allows the administrator to create an explicit allowlist of the team laptops' hardware addresses, so only those registered MAC addresses are permitted to associate with the network. This directly addresses the requirement to limit access to a known set of devices regardless of credentials.

Concept tested: Wireless access control using MAC filtering

Source: https://www.cisco.com/c/en/us/support/docs/smb/wireless/cisco-small-business-100-series-access-points/smb2099-mac-address-filtering-on-the-wap100-and-wap200-series.html

Topics

#MAC filtering#wireless security#access control#network access restriction

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice