A town IT lead notices visitors can be tricked by fake captive-portal pages on cleartext HTTP. What hardening direction should CWSP guidance favor?
Select an answer to reveal the explanation.
Short Explanation
A cleartext portal is a cardboard badge anyone can photocopy. Put the real AUP page behind TLS and teach people what the city’s genuine portal looks like. Telnet banners and WEP beacons are not a modern guest onboarding plan.
Full Explanation
HTTP captive portals are vulnerable to phishing lookalikes and on-path manipulation; TLS for portal presentation plus user awareness reduces that risk. Telnet and WEP are deprecated or inappropriate for portal authenticity. Breaking DNS wholesale disrupts legitimate onboarding rather than hardening the portal design.