WLAN Security Design and Architecture
CWSP · 150 questions
- A small municipal field office has no RADIUS server but still needs strong personal-mode Wi-Fi authentication. What should the designer select?
- Home-lab training gear at a county academy only supports WPA2-Personal. How should instructors contrast it with WPA3-Personal?
- Corporate laptops and Active Directory identities exist for city staff. Which WLAN authentication design is appropriate?
- A high-security government WLAN policy demands WPA3-Enterprise 192-bit mode. What should the architect select?
- A civic WLAN design requires port-based network access control for Wi-Fi clients. Which framework provides that model?
- A municipal operations center needs every staff AP to check user credentials against a central AAA store before granting WLAN access. Which authentication service belongs in that design?
- County policy requires mutual certificate authentication for staff laptops on the corporate SSID. Which EAP method best meets that requirement?
- A city library has specialty tablets that cannot store client certificates but can send a username and password inside a TLS tunnel to RADIUS. Which EAP method fits that constraint?
- A transit agency’s Windows-heavy fleet will authenticate to staff Wi-Fi with usernames and passwords protected inside a TLS tunnel, typically using MSCHAPv2. Which EAP method is that common pattern?
- Visitors to city hall need Internet-only Wi-Fi and must not use staff directory credentials. What authentication path should the designer choose?
- Policy forbids a single shared passphrase for roughly 500 municipal employees on the primary staff SSID. Which authentication design complies?
- City utilities IoT sensors cannot perform 802.1X, and operations proposed one global PSK on an open SSID. Which authentication approach is most appropriate for those constrained devices?
- During a county WLAN migration, some staff clients only support WPA2-Enterprise while newer laptops support WPA3-Enterprise. How should authentication be selected?
- When the city’s RADIUS servers are unreachable, engineers propose configuring Enterprise SSID APs to fail open and allow all associations. What is the correct security design stance?
- A county facility must choose guest Wi-Fi authentication: sponsor email approval versus open-on-click self-registration. What should drive the selection?
- A PKI-mature campus already issues managed device certificates and wants the strongest common enterprise WLAN EAP choice among TLS, TTLS, and PEAP. Which selection best fits?
- Retail-facing city HQ wants machines to authenticate to Wi-Fi before user logon and users to authenticate afterward for staff access. Which design direction is appropriate?
- Public kiosk tablets at the clerk’s office will use a guest-style SSID. Why must that SSID avoid the staff RADIUS realm?
- A parks department small site will use Personal mode. Why is WPA3-Personal with SAE preferred over classic WPA2-Personal PSK authentication?
- Contractor badges at a municipal data center map to Active Directory groups that should control Wi-Fi access. Which authentication approach should be selected?
- Security wants to mandate WPA3-Enterprise 192-bit mode on the courthouse SSID. What must be verified first?
- A small municipal field office SOHO-class AP offers WPA3 Transition for Personal mode versus SAE-only. How should the mode be chosen?
- A university-affiliated city training campus wants eduroam-style federated Wi-Fi for visiting researchers. Which authentication pattern is required?
- Guest Wi-Fi at the civic center uses an email click-through portal, while the staff SSID uses PEAP. What design principle should remain true?
- A weekend farmers-market booth network has no certificates, no directory, and only a passphrase for a temporary AP. Which authentication choice fits?
- Enterprise APs at the water utility authenticate users via RADIUS, but the AP-to-AAA shared secret remains the vendor default. What is wrong with that authentication design?
- Policy requires phishing-resistant WLAN authentication using device certificates for municipal laptops. Which EAP method should be selected?
- Guest access for the public library must not accept staff Active Directory passwords on the captive portal. What should the designer do?
- A facilities manager claims hiding the courthouse SSID provides confidentiality for wireless frames. Which statement corrects that misunderstanding?
- For a standard WPA2 enterprise redesign at city hall, which pairwise cipher should replace deprecated TKIP?
- A city library is designing a WPA3-Enterprise SSID for staff tablets. Beyond CCMP, which modern encryption protocol should the security architect also recognize as a valid Galois/Counter Mode option in current Wi-Fi suites?
- During a county hospital WLAN security design review, an engineer asks what cryptographic algorithm underlies both CCMP and GCMP. Which answer correctly separates the algorithm from the protocol wrapper?
- A municipal utilities yard is moving IoT gateways to WPA3-Personal. A technician claims SAE is “the encryption cipher that scrambles every data frame.” How should the security designer correct that statement?
- City cybersecurity policy for a classified records WLAN requires WPA3-Enterprise 192-bit security. Which encryption/AKM selection best matches that requirement?
- A county transit hub wants a password-free public SSID that still protects riders from casual passive sniffing on the RF. Which encryption approach should the architect select?
- Remote county clinicians work from hotel and coffee-shop Wi-Fi to reach clinic EHR apps. Link crypto on those foreign SSIDs is unknown. What additional control should the WLAN security design require for application traffic?
- A new WPA3 WLAN for city hall staff must choose modern data encryption. How should the designer compare CCMP and GCMP at selection time?
- Campus IT proposes terminating every city employee laptop into a VPN concentrator instead of deploying 802.1X on the corporate SSID. What is the sound security-architecture position?
- A parks department guest SSID uses only a captive portal for Acceptable Use acceptance. Auditors ask how RF frames are encrypted for casual visitors. What should the architect explain?
- A vendor proposes enabling TKIP “for compatibility” on a brand-new municipal public-safety WLAN. Which encryption decision aligns with current security design practice?
- While documenting the city council chamber SSID, the architect must explain encryption key roles at a design level. Which statement is accurate?
- County policy requires AES-CCMP for the assessor’s office WLAN and forbids mixed TKIP/AES profiles. A controller template still offers “TKIP+AES” mixed mode. What should the designer do?
- Outside contractors on the city’s guest SSID must reach a few internal project apps without placing those apps on the open guest VLAN. Which control best fits the encryption/security design?
- A city HR pilot wants WPA3-Enterprise 192-bit mode, but many older staff phones lack that suite. What encryption-selection constraint must the architect respect?
- A municipal visitor WLAN still has legacy open clients that cannot perform OWE. Leadership wants encryption for capable devices without stranding the rest overnight. Which OWE deployment choice fits?
- A security whiteboard at the water treatment plant labels “CCMP/GCMP” as protecting all 802.11 management and data frames equally. What correction belongs in the design notes?
- A city stadium Wi-Fi design needs continuous RF security monitoring with dedicated sensors that are not busy serving fans. Which wireless monitoring approach should the architect select?
- A small-town civic center has budget for security monitoring but not a second sensor grid. Serving APs can share scanning duty. Which WIPS approach fits?
- During a county courthouse WLAN cutover, engineers must validate EAPOL exchanges on the new secure SSID. Which on-site monitoring tool best fits that packet-level check?
- After jamming-like symptoms hit the municipal warehouse WLAN, responders need to hunt non-Wi-Fi interference and energy patterns. Which laptop-kit tool should lead that RF investigation?
- Serving APs at a busy city convention center cannot spend enough time off-channel without hurting client performance. Security still needs continuous multi-channel visibility. Which WIPS selection follows?
- City SOC requirements say the WLAN monitoring system must alert when a rogue AP advertises the same corporate SSID. Leadership offers only switch SNMP uptime polls. What capability gap must be closed?
- Before city-wide rollout, a pilot must prove OWE and SAE handshakes complete as designed on sample APs. Which monitoring activity validates that security design?
- A week-long outdoor civic festival needs short-term WLAN security oversight without a permanent sensor build-out. Which monitoring approach is most appropriate?
- In the city’s RSN design guide, what does Authentication and Key Management (AKM) define for an 802.11 Robust Security Network?
- A county facilities WLAN finishes either PSK or 802.1X authentication for building-inspector tablets. What is the primary purpose of the 4-way handshake that follows?
- City IT is retiring WPA2-Personal on the parks-crew SSID because offline dictionary attacks against a shared passphrase keep succeeding in audits. Which WPA3-Personal AKM mechanism should replace that password-based design?
- A municipal library wants an open guest SSID that still encrypts each patron’s unicast traffic without distributing a passphrase. Which exchange enables that opportunistic encryption?
- Transit-authority officers roam between platform APs while staying on a secure enterprise SSID. Which AKM-related construct specifically supports fast secure handoffs under 802.11r?
- A town clerk’s office uses one Wi-Fi passphrase for every inspector laptop under WPA2/WPA3-Personal. Where does that design place the pre-shared key in AKM terms, and what operational risk follows at municipal scale?
- County public-health clinicians authenticate to the clinic WLAN with usernames and certificates through a RADIUS server. In what order does Enterprise AKM establish security for their sessions?
- During a city WLAN design review, the security architect asks how clients learn which AKM suites and pairwise ciphers an AP supports before associating. Which element advertises those RSN capabilities?
- A municipal CIO asks which Wi-Fi Alliance security generation should be treated as deprecated when selecting AKM for new city-hall SSIDs, relative to WPA2 and WPA3.
- Public-works still has a few WPA2-only rugged tablets while newer crew phones support WPA3. Leadership enables WPA3 Transition Mode on the field SSID. What security tradeoff should the CWSP candidate emphasize versus SAE-only?
- Campus Wi-Fi engineers debate two different knobs while migrating city buildings to stronger AKM: WPA3 Transition Mode versus RSN Override. How should a CWSP candidate distinguish them at a conceptual level?
- In a court-house WLAN design workshop, staff confuse PMK, PTK, and GTK roles. Which statement correctly maps the key hierarchy concepts?
- Fire-station tablets use 802.11r while paramedics move through the apparatus bay. At a conceptual AKM/roaming level, how do FT over-the-air and FT over-the-DS differ?
- A parks department insists CCMP is enabled on their Personal SSID, yet auditors still crack the network after capturing a handshake because the passphrase is “Parks2024!”. What AKM lesson should the security lead draw?
- Compared with a single shared PSK on the utilities field SSID, what security property does Enterprise AKM add when linemen authenticate with unique credentials?
- A scan of city-hall beacons during WPA3 migration shows both WPA2 and WPA3 AKM suites advertised on the same SSID. How should the candidate interpret that mixed advertisement?
- The city wants downtown kiosk Wi-Fi to remain passphrase-free for tourists yet still encrypt each device’s unicast frames. Which AKM should the design select for that open SSID goal?
- Clinic tablets receive Access-Accept from RADIUS, yet the 4-way handshake fails and no user-plane traffic flows. Conceptually, what should the municipal WLAN team investigate first among AKM issues?
- After several inspectors leave the permit-counter BSS, the WLAN still needs to refresh keys used for broadcast/multicast frames to remaining stations. Which handshake concept addresses that group-key renewal?
- In a mixed client environment at city libraries, engineers want capable devices to prefer stronger RSN suites rather than settling for weaker transition options. What is the conceptual purpose of RSN Override in that design?
- Policy for new community-center SSIDs requires a WPA3 security baseline. Which deprecated options must the design reject as AKM/cipher choices under that baseline?
- Before approving the next municipal WLAN architecture review, security leadership wants a written allowlist of AKM suites (for example SAE and 802.1X-SHA256) that APs may advertise. Why does that policy artifact matter?
- An auditor notes that unused Ethernet wall jacks in a civic center could let someone plug in a rogue AP. Which wired support control best addresses that physical attachment risk at the switch edge?
- Wiring-closet reviews for county buildings show many switchports enabled with no connected device. What physical/port-security practice should WLAN-supporting network teams apply?
- A city WLAN carries employee laptops, guest tablets, and building IoT sensors on the same SSID and VLAN today. Which segmentation approach best aligns with layered WLAN-supporting security?
- A municipal security architect describes defense-in-depth for WLAN user traffic as it leaves the air and enters the wired campus. Which stacked control set best matches that layered approach?
- A city library WLAN must keep user VLANs centralized on the wireless controller rather than switching locally at each AP. Which architecture pattern best meets that design goal?
- County IT wants guest Wi-Fi traffic kept out of the campus core and terminated in a DMZ. Which approach best supports that isolation goal?
- A municipal guest VLAN must reach the Internet but must not talk to staff servers. Where should ACLs primarily enforce that Internet-only restriction?
- A public health clinic’s IoT WLAN segment must not reach electronic health record (EHR) servers. Which control best limits that lateral movement?
- City hall separates a guest WLAN VLAN from corporate services. Which device role should sit between those segments to inspect and filter that traffic?
- Remote city workers often join from untrusted café Wi-Fi, then VPN into municipal systems. What firewall posture best fits that path?
- Campus switches terminate city APs. Which port-hardening pair best protects those AP attachment points?
- A county WLAN design discussion focuses on microsegmentation after 802.1X. How should WLAN roles typically map for segmentation?
- Remote inspectors use external WLANs and VPN back to county systems. Leadership asks about split-tunnel versus full-tunnel. What is the key security-architecture distinction?
- Guest-to-staff deny ACLs protect a civic WLAN. How should those ACLs also support operations beyond silent blocking?
- A compromised Wi-Fi laptop on the city network begins unusual lateral protocols toward internal hosts. Which control is best positioned to identify that behavior in transit?
- Policy requires least privilege on AP switch drops across city buildings. Which VLAN-trunk practice best matches that hygiene?
- A remote branch must connect its AP/controller WLAN path across the public Internet back to headquarters. Which protection best fits that untrusted WAN transit?
- Designers want an AP switchport to shut if someone swaps the AP for a soft-AP phone bridge. What design intent does a port-security violation shutdown express?
- After login on a hospital-affiliated city clinic WLAN, clinicians and guests must receive different network privileges. Which model best describes that outcome?
- A transit agency wants one enterprise SSID but different network rights per job function. Which RBAC pattern best achieves that?
- The city plans WPA-Enterprise with EAP-TLS for staff laptops. What foundational service must exist for client and server certificates?
- Staff laptops use 802.1X against city RADIUS. Which PKI-dependent client behavior best helps stop an evil-twin AP impersonating the enterprise SSID?
- Architects describe why enterprise WLAN should use AAA rather than only local AP user databases. What purpose do AAA servers primarily serve?
- City WLAN must stay available if one RADIUS server fails, but must not admit users without authentication. Which AAA design best fits?
- Before staff devices first associate to the secure city SSID, credentials or profiles must be installed safely. What does that client-onboarding goal emphasize?
- A university-affiliated municipal campus offers a self-service portal that issues unique WLAN credentials. What design caution still applies?
- County policy requires wireless staff devices to show healthy antivirus posture before receiving the full staff VLAN. Which control implements that gate?
- Some wireless clients fail NAC posture on the city WLAN. Which network response best supports remediation without full staff access?
- Employees bring personally owned phones onto the enterprise city SSID. Which control family best addresses corporate data on those BYOD devices?
- A city IT team manages tablets used by building inspectors on the staff WLAN. How should MDM best reduce evil-twin risk for EAP?
- Contractors authenticate successfully to the municipal Wi-Fi, but policy must still keep them off finance SSID resources. Which control enforces that after authentication?
- Field tablets for public-works crews sometimes lack Internet paths when validating certificates during EAP. What PKI concern should the WLAN security design address?
- After suspicious Wi-Fi logins at city hall, investigators need evidence of who authenticated, when, and from which session. Which AAA function best supplies that telemetry?
- Facilities wants a permanent open SSID named Enroll-City so any device can grab certificates. What onboarding design principle should security enforce instead?
- The county health campus wants posture checks before full staff VLAN access on Wi-Fi. Where does NAC belong in that architecture?
- A council member’s unmanaged personal phone requests the high-trust finance SSID. Policy requires MDM for that SSID. What should the design do?
- WLAN engineers must choose trust anchors for RADIUS server certificates used by city EAP clients. Which design choice is most accurate?
- The city plans to back Wi-Fi identity with a cloud IdP through an AAA proxy. Which architecture statement remains true?
- Headless IoT meters in city facilities cannot run 802.1X clients. What onboarding approach best improves accountability versus one shared PSK?
- Managed phones for code-enforcement staff must be MDM-compliant before gaining staff WLAN rights. How should the controls work together?
- Dispatch voice handsets roam across city-yard APs and drop syllables during full 802.1X each hop. Which secure roaming feature should the design select first?
- A candidate claims Fast BSS Transition simply turns off encryption during roam. What is the correct CWSP-level understanding?
- A mixed-vendor municipal campus needs faster secure reassociation without depending solely on 802.11r client support. Which technique fits that conceptual need?
- For a city voice SSID, engineers must choose between 802.11r FT and OKC. What selection guidance is most appropriate?
- Facilities proposes one shared PSK for all yard tablets because roaming is simple. What security tradeoff must leadership accept?
- Library kiosks and volunteer tablets need Personal-mode Wi-Fi without one citywide passphrase. Which approach improves accountability?
- Some city scanners misbehave with FT enabled, so ops plans to disable it on that SSID. What operational tradeoff should they expect?
- During a design review, staff ask how OKC speeds secure reassociation across city APs. What is the core idea?
- A vendor claims per-user PSK gives the city the same security properties as WPA3-Enterprise 802.1X. What is the accurate distinction?
- Secure transitioning for ambulance tablets across hospital-campus APs must satisfy which rule?
- In a controller-based city WLAN using 802.11r, what conceptual roles do FT key holders play?
- Warehouse barcode scanners fail when 802.11r is enabled on the logistics SSID. What is a reasonable secure-roaming response?
- City visitor Wi-Fi must not reach staff file shares or internal VLANs. Which guest-access design best meets that goal?
- On the public library guest SSID, attackers could pivot laptop-to-laptop if clients talk freely. What control best stops that lateral path?
- A city visitor-center WLAN must show guests an acceptable-use policy and record acceptance before Internet access begins. Which design best meets that goal?
- A municipal tourism board wants visitors’ phones to join partner hotspots automatically with stronger onboarding than a shared PSK poster. Which approach best matches that goal?
- A library board wants a password-free ‘open’ municipal SSID that still encrypts airtime against casual sniffing. Which control should the WLAN designer select?
- A county parks department is hardening free public Wi-Fi. Which guest design best layers public-access controls?
- A city conference-center SSID will host vendor demos that sometimes need AirDrop-like peer-to-peer transfers. How should the security designer treat peer-to-peer policy?
- A town IT lead notices visitors can be tricked by fake captive-portal pages on cleartext HTTP. What hardening direction should CWSP guidance favor?
- Regional transit riders roam across city hotspots and still receive paper PSK cards. Which Passpoint-oriented change best reduces that manual credential problem?
- A civic plaza SSID must encrypt public airtime and still force guests through an AUP page. Which statement is most accurate?
- A borough proposes a downtown ‘open’ SSID with neither a captive portal nor OWE. From a modern public-access security design view, what is the best assessment?
- A city-owned visitor lodge must choose a guest Wi-Fi credential model. How should the WLAN security designer decide between per-room credentials and open+OWE?
- During a municipal WLAN hardening review, outdoor APs and the controller still use factory administrator passwords. What should be done first?
- A city help desk discovers the staff SSID accidentally maps guests to the same open VLAN as employees. What preventative focus best addresses this class of failure?
- County WLAN APs have known CVEs fixed only in newer firmware. Which preventative measure aligns with CWSP infrastructure hardening?
- A municipal WLAN controller still allows cleartext HTTP for the admin GUI. What should the hardening plan require?
- Field techs still use Telnet to the city’s outdoor AP CLI. What preventative change should security mandate?
- A library WLAN still runs SNMPv2c with the community string ‘public’ on APs. What should the designer do?
- A new outdoor AP for a transit shelter still accepts ‘admin/admin’. How should a hardening assessment treat that finding?
- After a template push, several city APs re-enable HTTP admin that security had disabled. What preventative discipline best stops this regression?
- Vendor support ends for AP code that still has unpatched remote flaws on a municipal campus. What preventative path remains when patches will never ship?
- A city WLAN team wants one management-plane hardening baseline for controllers and APs. Which combination best matches preventative practice?