A county CIO authorizes a WLAN penetration test of the civic center. What must the security team lock before any active testing begins?
Select an answer to reveal the explanation.
Short Explanation
Authorized WLAN testing is not a free-for-all scavenger hunt. Put the fences on paper first—scope, SSIDs, buildings, and a signed green light. Without that, “help” looks a lot like an attack.
Full Explanation
Structured WLAN penetration testing begins with clear rules of engagement and documented authorization so active techniques stay legal, ethical, and operationally safe. Scope should identify SSIDs, locations, timing windows, and prohibited actions such as disrupting public-safety or emergency networks. Verbal-only approval and unscoped cracking introduce liability and outage risk. Proving impact by mass deauthentication is rarely appropriate without explicit approval and is not a substitute for a controlled test plan.