Outside contractors on the city’s guest SSID must reach a few internal project apps without placing those apps on the open guest VLAN. Which control best fits the encryption/security design?
Select an answer to reveal the explanation.
Short Explanation
Guest Wi-Fi is the lobby—internal apps live behind the badge door. A VPN concentrator lets contractors carry an encrypted tunnel from that lobby to the apps without pouring the app VLAN onto the guest SSID. Bridging guest straight inside is the opposite of segmentation.
Full Explanation
Guest or open WLAN paths should remain segmented from internal application networks. When contractors must reach internal apps, a Layer 3 VPN provides authenticated, encrypted access without flattening guest and internal VLANs together. Cleartext portal links and direct bridging expand exposure. VPN selection in this scenario aligns with using VPN as an additional security layer over WLAN paths.