Vendor default profiles on city APs include a 'WPA/WPA2 mixed' mode that still enables TKIP for compatibility. How should that default be treated?
Select an answer to reveal the explanation.
Short Explanation
Mixed WPA/WPA2 with TKIP still allowed is a compromise buffet—the weakest diner picks the meal. For city APs, shut off those defaults and serve only modern ciphers.
Full Explanation
WPA/WPA2 mixed profiles often permit TKIP or other legacy options for backward compatibility, reintroducing deprecated cryptography. Security engineers should disable such defaults and enforce WPA2/WPA3 configurations with AES-based ciphers. Mixed mode is not equivalent to modern high-assurance suites.