A zero-day affects AP OS images on the municipal mesh with no vendor patch yet, but compensating WIPS signatures are available. What mitigation approach fits best?
Select an answer to reveal the explanation.
Short Explanation
No patch yet does not mean nap time. Turn on the WIPS signatures you have, quarantine the juiciest APs, and babysit the municipal mesh until the vendor drops a fix.
Full Explanation
When immediate patches are unavailable, Domain 2.1.3 mitigation includes compensating controls such as enhanced WIPS detection and quarantine of unrepaired high-risk systems. Idle waiting or weakening encryption increases exposure; sharing credentials is unsafe. Combining monitoring with isolation pending upgrade is appropriate for zero-day WLAN infrastructure risk.