Campus IT proposes terminating every city employee laptop into a VPN concentrator instead of deploying 802.1X on the corporate SSID. What is the sound security-architecture position?
Select an answer to reveal the explanation.
Short Explanation
On campus, 802.1X is the badge reader at the building door; VPN is the armored truck you use on the public highway. You do not rip out the badge system because trucks exist. Use both in the right places—enterprise link auth on the corporate SSID, VPN when the path is untrusted.
Full Explanation
Enterprise campus WLANs should authenticate and encrypt at the link layer with 802.1X-based WPA2/WPA3-Enterprise designs. VPN is complementary for remote or otherwise untrusted networks and for protecting higher-layer sessions, but it does not remove the need for strong SSID authentication and encryption on campus. Open SSIDs with VPN-only thinking, PSK-only shortcuts, or MAC filtering alone weaken the architecture. Proper placement of VPN versus link security is a CWSP design judgment.