Citizens report captive-portal lookalikes near a municipal plaza guest network. Which defensive approach best addresses evil-twin / MitM patterns?
Select an answer to reveal the explanation.
Short Explanation
Evil twins wear the city’s SSID like a fake badge at the festival gate. Spot them with wireless IDS/IPS and watchful ops, tell people how the real guest network looks, and harden the real service. Posting secrets on a sandwich board is not a detection strategy.
Full Explanation
Defending against evil-twin and MitM-style attacks on municipal captive portals combines WIDS/WIPS detection of spoofed SSID/BSSID and portal anomalies, user guidance to sanctioned onboarding, and hardening of the legitimate guest path (certificates, WPA3/OWE where applicable, monitoring). Publishing PSKs publicly, disabling sensors, or pushing unofficial VPN sideloads increases risk and is not sound IDP practice.