Facilities wants a permanent open SSID named Enroll-City so any device can grab certificates. What onboarding design principle should security enforce instead?
Select an answer to reveal the explanation.
Short Explanation
A forever-open Enroll-City SSID is like leaving the loading dock unlocked because someone might need a badge later. Controlled, short-lived onboarding beats a permanent soft underbelly next to production. Parking finance on that dock is worse.
Full Explanation
Client onboarding must provision credentials or profiles without creating a lasting weak wireless edge. Permanent open enrollment SSIDs expand eavesdropping and abuse risk and often become unmanaged attack paths. Prefer secured, time-limited, or out-of-band enrollment that leaves production SSIDs at policy strength.