Policy requires phishing-resistant WLAN authentication using device certificates for municipal laptops. Which EAP method should be selected?
Select an answer to reveal the explanation.
Short Explanation
Phishing loves passwords typed into look-alike portals. Device-cert EAP-TLS skips that trap. PEAP passwords, MD5, and captive AD logins are still phish bait.
Full Explanation
EAP-TLS authenticates with client certificates and is substantially more phishing-resistant than password-based EAP methods or captive portals that solicit directory passwords. When policy demands phishing-resistant WLAN auth with device certs, EAP-TLS is the appropriate selection over PEAP-MSCHAPv2, EAP-MD5, or portal password collection.