Security Policy
CWSP · 30 questions
- A city retail concession on the waterfront must process card payments over Wi-Fi for POS tablets. Which WLAN security requirement best reflects PCI-DSS expectations for that wireless path?
- A county clinic is rolling out clinic-wide Wi-Fi for clinician tablets that may display ePHI. What should the WLAN security requirements gathering emphasize under HIPAA-oriented expectations?
- A European municipal visitor center will collect guest email addresses through the Wi-Fi captive portal for marketing. Which requirement should WLAN security policy work incorporate under GDPR?
- A regional transit agency asks for "strong Wi-Fi security" but has not written business goals for ops tablets versus public rider Wi-Fi. What should the security professional do first when forming WLAN security requirements?
- Municipal IT drafts a citywide wireless security policy without involving legal, compliance, or facilities. Which gap most undermines an enforceable WLAN security policy?
- A county hospital redesigns clinical Wi-Fi but omits clinical engineering and biomedical device owners from requirements workshops. Why is that a stakeholder problem for WLAN security policy?
- A city WLAN security review inventories only access points and ignores controllers, RADIUS, and DHCP. What should the infrastructure review include for security requirements?
- Before writing WLAN policy, a municipal warehouse team inventories only managed laptops and skips BYOD phones and barcode scanners. Which requirements input is missing?
- A city warehouse adds rugged scanners that only support an older TLS stack. How should that client constraint affect WLAN security requirements?
- A state university WLAN review finds consumer mesh extenders bridged onto the campus staff SSID. What should the infrastructure review conclude for policy?
- Technical requirements say "encrypt everything," but the city council needs board-readable WLAN security policy. What should the security professional produce?
- A draft municipal WLAN policy lists a single vendor's product SKUs instead of security outcomes. Which rewrite best follows high-level policy practice?
- City leadership wants WLAN security policy "based on industry standards" without inventing home-grown crypto rules. What advice aligns with CWSP policy practice?
- A small municipal office proposes copying a 2008 WLAN policy template that still allows WEP. What should the advisor recommend?
- A county writes WLAN security policy once, then never revisits it after major controller and WPA3 upgrades. Which lifecycle action is missing?
- After a city adopts WPA3-Enterprise, temporary WPA3 Transition Mode exceptions remain in policy with no end date. What lifecycle practice should be applied?
- Network engineers publish a city WLAN security policy on an internal wiki with no executive sign-off. What is required before the policy can be treated as enforceable?
- A public school district needs enforceable acceptable-use rules for guest Wi-Fi used by visitors and events. Who should approve that guest WLAN policy content?
- Helpdesk staff at a municipal utility still tell employees to share the staff WLAN PSK. Which Domain 1 control most directly addresses this behavior?
- New contractors arrive on a city plant floor with no briefing on how to report suspected rogue APs. What should WLAN security awareness cover for these stakeholders?
- City finance purchases outdoor APs "for cameras" and ships them for install without a security review. What Domain 1 practice was skipped?
- A city museum wants open Wi-Fi for visitors and a separate secured WLAN for exhibit sensors. How should security requirements be derived?
- A municipal WLAN policy lists only the CISO as owner; network operations never receives updates. Which stakeholder gap should be fixed?
- An audit finds city policy mandates certificate-based EAP, but nobody reviewed which line-of-business apps break with mutual TLS client auth. What requirements step was skipped?
- A county WLAN moves to cloud-managed controllers, but security policy still assumes only on-premises admin paths. What should the infrastructure requirements review update?
- A county WLAN draft only says staff shall not do bad things on Wi-Fi and lists no enforceable rules. How should the security lead rewrite it into high-level policy statements?
- Industry hardening guidance for the city's WLAN controllers calls for unique administrator credentials and disabling legacy SNMP. What should the CWSP advise when building WLAN security policy?
- A municipal WLAN security policy was approved last year, but no review calendar exists. What lifecycle step is missing?
- City IT enables aggressive WIPS blocking on the civic-center WLAN without documented approval, and facilities staff complain that legitimate devices are disrupted. What should have happened first?
- The county's quarterly phishing drills only use email lures and never mention fake captive portals or evil-twin Wi-Fi prompts. What awareness gap should the CWSP flag?