Staff receive phishing messages asking them to “re-enter Wi-Fi credentials” on a lookalike city portal. What mitigation belongs in the WLAN security program?
Select an answer to reveal the explanation.
Short Explanation
Phishing for Wi-Fi passwords is social engineering with an antenna. Train people, point them at the real join path, and lean on designs that don’t live or die on a shared secret people will type into fake pages. Reusing Wi-Fi passwords everywhere is pouring gasoline on the problem.
Full Explanation
Social-engineering attacks targeting WLAN credentials are mitigated by awareness training, verified onboarding URLs/apps, and architectures that minimize phishable PSKs (e.g., 802.1X/EAP-TLS, curated guest flows). Treating phishing as email-only ignores Wi-Fi-specific lures. Credential reuse and publishing PSKs in messages expand compromise blast radius.