nerdexam
CompTIA

SY0-301 · Question #641

Jane, the security administrator, sets up a new AP but realizes too many outsiders are able to connect to that AP and gain unauthorized access. Which of the following would be the BEST way to…

The correct answer is C. Enable MAC filtering D. Disable SSID broadcast. Two effective controls work together here. MAC filtering (C) creates an explicit allowlist of device hardware addresses permitted to associate with the AP; any device whose MAC address is not on the list is denied a connection regardless of whether it knows the passphrase…

Security architecture

Question

Jane, the security administrator, sets up a new AP but realizes too many outsiders are able to connect to that AP and gain unauthorized access. Which of the following would be the BEST way to mitigate this issue and still provide coverage where needed? (Select TWO).

Options

  • ADisable the wired ports
  • BUse channels 1, 4 and 7 only
  • CEnable MAC filtering
  • DDisable SSID broadcast
  • ESwitch from 802.11a to 802.11b

How the community answered

(47 responses)
  • A
    2% (1)
  • C
    94% (44)
  • E
    4% (2)

Explanation

Two effective controls work together here. MAC filtering (C) creates an explicit allowlist of device hardware addresses permitted to associate with the AP; any device whose MAC address is not on the list is denied a connection regardless of whether it knows the passphrase. Disabling SSID broadcast (D) hides the network name from passive scans, so casual or opportunistic users never see the network to attempt a connection. Together these raise the barrier to unauthorized access without reducing RF coverage. The other options are distractors: disabling wired ports (A) has no effect on wireless clients; using only channels 1, 4, and 7 (B) is not standard channel planning and does nothing for access control; switching from 802.11a to 802.11b (E) lowers throughput and changes the frequency band but provides no security benefit.

Topics

#MAC filtering#SSID broadcast#wireless security#access point hardening

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice