Staff laptops use 802.1X against city RADIUS. Which PKI-dependent client behavior best helps stop an evil-twin AP impersonating the enterprise SSID?
Select an answer to reveal the explanation.
Short Explanation
Evil twins love clients that shrug at server certificates. Make laptops validate the RADIUS server cert before finishing 802.1X. Blind trust is how impostors win.
Full Explanation
Client validation of the AAA/RADIUS server certificate is a PKI-dependent control that helps defeat evil-twin APs advertising a familiar enterprise SSID. Without server-certificate checks, users may authenticate to an attacker-controlled authenticator. Disabling trust stores or blanking validation weakens that defense for municipal endpoints.