Vendor defaults on a new branch-library AP still allow WPA-PSK with TKIP. How should the technician harden the config?
Select an answer to reveal the explanation.
Short Explanation
Factory defaults are not a security policy. Turn off the WPA-PSK/TKIP leftover and lock the library AP to a modern WPA2 or WPA3 AES/CCMP suite before patrons show up.
Full Explanation
Technicians must not accept insecure vendor defaults. Disabling WPA-Personal with TKIP and enabling WPA2 or WPA3 with AES/CCMP aligns the AP with modern secure configuration expectations. Daily PSK rotation, radio-split excuses, or waiting on future firmware do not remediate an active TKIP/WPA1 option.