Wireless Security, IDP, and WIPS
CWNE · 60 questions
- A city payments kiosk SSID may process cardholder data and sits near HIPAA-adjacent clinic check-in devices. What should security policy authors do first?
- During a stakeholder workshop for civic guest Wi-Fi, IT security and the communications office disagree about Acceptable Use. What should the session establish?
- After a city migrates enterprise SSIDs to WPA3-Enterprise, what policy-lifecycle action is most appropriate?
- Facilities staff keep plugging consumer APs into wall jacks behind reception desks, creating rogue SSIDs. Which program element most directly addresses the root behavior?
- A vulnerability bulletin lists a high-impact CVE in the city’s AP firmware train. What is the sound vulnerability-management response?
- A municipal open guest SSID provides no OWE and no other Layer-2 encryption. What threat should policy and design explicitly recognize?
- Citizens report captive-portal lookalikes near a municipal plaza guest network. Which defensive approach best addresses evil-twin / MitM patterns?
- A parks festival SSID uses WPA2-Personal with a short, guessable passphrase shared on flyers. What cracking-related risk should drive a redesign?
- Staff receive phishing messages asking them to “re-enter Wi-Fi credentials” on a lookalike city portal. What mitigation belongs in the WLAN security program?
- A legacy SCADA SSID in a utilities plant still permits WEP and TKIP. What threat-driven action is required?
- A county CIO authorizes a WLAN penetration test of the civic center. What must the security team lock before any active testing begins?
- A multi-vendor municipal campus needs consistent rogue detection across controllers from different manufacturers. Which WIPS approach best fits?
- The city SOC needs 24/7 visibility into wireless threats. How should WIDS alerts be handled?
- Justice-system WLAN policy demands the strongest WPA3 enterprise mode for courthouse staff devices. Which design choice aligns?
- Small city satellite offices still use WPA2-PSK for a handful of staff laptops. What should replace that AKM for stronger personal-mode security?
- City laptops already enroll in a managed PKI. Which EAP method best matches that certificate maturity for employee WLAN?
- Municipal employee WLAN depends on 802.1X. How should RADIUS/AAA be designed for resilience?
- An engineer reviewing RSN settings for a WPA3 civic SSID must distinguish modern pairwise ciphers. Which statement is accurate?
- A public library wants open guest Wi-Fi without a shared password, yet still needs encryption on the air. What should the design use?
- City guest Wi-Fi must onboard visitors, stop guest-to-guest snooping, and limit bandwidth abuse. Which control set fits?
- A convention center for municipal events wants scalable visitor onboarding without SMS captive portals. Which approach aligns?
- Voice SSID roaming must stay fast without weakening WPA3 security on city handsets. What is the sound approach?
- Municipal IoT sensors cannot perform 802.1X. Which onboarding pattern best limits blast radius versus one global PSK?
- Before city employees reach the corporate SSID, devices must prove patch and disk-encryption posture. Which control provides that gate?
- Contractors on the civic WLAN must land in a restricted role and VLAN via AAA. How should that be enforced?
- Rogue APs keep appearing when someone plugs unauthorized gear into empty wall jacks near city meeting rooms. What wired control helps most?
- City WLAN carries corporate, guest, and IoT SSIDs. What wired-side practice is essential?
- An IoT VLAN hosts municipal security cameras that should not freely reach workstation subnets. What should limit east-west movement?
- AP management planes in city halls still allow HTTP, Telnet, and SNMPv1. What hardening step is required?
- New outdoor APs for parks still ship with vendor default admin passwords. What baseline hygiene is mandatory before production use?
- WLAN security lifecycle for the municipality must include ongoing platform upkeep. Which practice belongs?
- An engineer wants to change the employee SSID from WPA3-Enterprise to a shared PSK “just for the weekend festival.” What process should stop that?
- Leadership asks how WLAN security health should be reviewed on a recurring basis. What audit practice fits?
- Risk ranking for city wireless assets must guide spending. How should public-safety WLAN be treated versus open guest Wi-Fi?
- WIPS detects a rogue AP advertising the city’s employee SSID near city hall. What response aligns with policy-driven containment?
- County sheriff deputies' laptops sometimes join a neighboring agency's SSID that overlaps City Hall's RF footprint. Beyond reminding staff of the acceptable-use policy, which combined approach best reduces misassociation risk?
- A municipality is rolling out EAP-TLS for thousands of city and school devices. Which CA and certificate-lifecycle consideration is most important at that scale?
- A school district places teacher BYOD tablets on a WPA3-Enterprise SSID. How should mobile device management (MDM) primarily support that security design?
- City inspectors must use hotel and conference Wi-Fi while traveling. What role should a VPN overlay play relative to the untrusted wireless LAN?
- Facilities still has a mix of WPA3-capable phones and older barcode scanners. Leadership asks whether to force strict WPA3 or allow a transition mode. What is the sound selection principle?
- A county SOC notices bursts of failed 802.1X authentications against the city RADIUS cluster. Why should authentication-failure logging be prioritized?
- NAC marks a contractor laptop non-compliant during posture check on the city employee SSID. What network design element best supports remediation?
- WLAN controllers for the transit authority sit in unlocked telecom closets shared with janitorial storage. Which hardening step belongs in the security architecture?
- Finance insists the tax-system SSID use a shared WPA2-Personal passphrase 'because it is simpler than 802.1X.' 802.1X infrastructure already exists. What architecture choice is appropriate?
- The city WLAN team plans to enable Wi-Fi 6E/7 features including 6 GHz operation. What security lifecycle step should precede broad enablement?
- A warehouse barcode scanner cannot support WPA3 and must remain on a constrained SSID. How should the exception be handled?
- During a festival hotspot event, WIPS reports floods of deauthentication frames targeting the city guest SSID. What is the appropriate defensive focus?
- Malware on one library guest laptop begins scanning other devices on the open public SSID. Which control best limits lateral movement?
- City network engineers currently manage outdoor APs over HTTPS from the public Internet using default accounts. What management-plane hardening is most appropriate?
- After a downtown channel replan, WIPS begins flagging many authorized APs as suspicious. What operational step should follow?
- Public-safety leadership asks what business impact analysis should capture if the dedicated public-safety WLAN becomes unavailable during an incident. What should that analysis emphasize?
- Controller admin accounts for the parks WLAN still use shared passwords without a second factor. What control best hardens administrative access?
- The county jail WLAN must remain highly isolated, while city corporate offices need segmented but interconnected services. What security-model takeaway applies?
- WIPS and switch logs show an employee laptop bridging the city WLAN to a personal hotspot via Windows Internet Connection Sharing. How should this be treated?
- Nightly backups of WLAN controller configurations include RADIUS secrets, certificates, and PSKs. How should those backups be protected?
- Auditors ask whether Management Frame Protection (PMF / 802.11w) is enabled on SSIDs that require it. What should the WLAN security design validate?
- Marketing wants visitor foot-traffic analytics SSIDs collocated with employee 802.1X SSIDs using the same VLAN and identity store. What design guidance applies?
- During a city council livestream, attendees report a suspected wireless man-in-the-middle near the chambers. What incident-response approach is most appropriate?
- A construction vendor plugs an unmanaged consumer AP into a city building VLAN without change control. How should this be classified and handled?
- Continuous monitoring shows RADIUS authentication volume climbing with new clinics joining the municipal WLAN. What capacity-planning action aligns with security-service lifecycle needs?