Municipal IoT sensors cannot perform 802.1X. Which onboarding pattern best limits blast radius versus one global PSK?
Select an answer to reveal the explanation.
Short Explanation
One giant IoT password is a master key taped to the fridge. Per-device or DPP-style onboarding lets you revoke one sensor without rekeying the city. Waiting a year with the door open is not a strategy.
Full Explanation
IoT endpoints that lack 802.1X still need constrained credentials. Per-user/per-device PSK and DPP-style onboarding reduce shared-secret blast radius and improve revocation compared with one global PSK. Placing unauthenticated IoT on privileged VLANs or running open until a future budget cycle leaves municipal networks exposed.