City utilities IoT sensors cannot perform 802.1X, and operations proposed one global PSK on an open SSID. Which authentication approach is most appropriate for those constrained devices?
Select an answer to reveal the explanation.
Short Explanation
If the gadget can’t do 802.1X, don’t shrug and leave the door open. WPA3-Personal SAE—or carefully managed per-device PSKs—beats ‘anyone may associate.’ Demanding certs the chip can’t hold, or rolling WEP, isn’t the win.
Full Explanation
802.1X-incapable IoT still needs link authentication and encryption. WPA3-Personal SAE improves on classic PSK weaknesses; some designs use unique PSKs per device. Open SSIDs, impossible EAP-TLS mandates, and WEP are poor choices. The design should avoid a single unmanaged global secret on an open network when Personal/SAE or per-device PSK patterns are feasible.