SY0-501 · Question #504
A security analyst is hardening a WiFi infrastructure. The primary requirements are the following: The infrastructure must allow staff to authenticate using the most secure method. The…
The correct answer is D. Configure a captive portal for guest and WPA2 Enterprise for staff. To meet the requirements, the security analyst should recommend WPA2 Enterprise for staff authentication due to its superior security, and a captive portal for guests to facilitate email-based access logging.
Question
A security analyst is hardening a WiFi infrastructure. The primary requirements are the following:
The infrastructure must allow staff to authenticate using the most secure method. The infrastructure must allow guests to use an "open" WiFi network that logs valid email addresses before granting access to the Internet. Given these requirements, which of the following statements BEST represents what the analyst should recommend and configure?
Options
- AConfigure a captive portal for guests and WPS for staff.
- BConfigure a captive portal for staff and WPA for guests.
- CConfigure a captive portal for staff and WEP for guests.
- DConfigure a captive portal for guest and WPA2 Enterprise for staff.
How the community answered
(58 responses)- A7% (4)
- B2% (1)
- C12% (7)
- D79% (46)
Why each option
To meet the requirements, the security analyst should recommend WPA2 Enterprise for staff authentication due to its superior security, and a captive portal for guests to facilitate email-based access logging.
WPS (Wi-Fi Protected Setup) is a convenience feature with known security vulnerabilities and is not considered the most secure authentication method for staff.
A captive portal is unsuitable for primary staff authentication, and WPA (likely WPA-PSK) requires a pre-shared key, contradicting the 'open' network requirement for guests.
A captive portal is inappropriate for staff's primary secure authentication, and WEP is an outdated, highly insecure encryption protocol that should never be used.
WPA2 Enterprise, leveraging 802.1X and a RADIUS server, provides robust, individual user authentication and strong encryption, making it the most secure method for staff. A captive portal fulfills the guest requirement by redirecting users to a web page for email registration before granting Internet access over an otherwise 'open' network.
Concept tested: Wi-Fi security protocols, authentication methods, and guest access solutions
Source: https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-802-1x-configure-nps
Topics
Community Discussion
No community discussion yet for this question.