Wi-Fi Encryption & Security Models
OSWP · 35 questions
- A city policy still allows WEP 'for old scanners' on a warehouse SSID. Why should assessors treat WEP as insecure?
- A museum gift-shop AP is configured for TKIP-only WPA. What should the candidate recognize?
- A library asks what WPA2-Personal actually shares among authorized users on the staff SSID. What is accurate?
- A clinic wants per-user accountability on staff Wi-Fi so departed employees can be revoked individually. Which model best fits?
- A parks guest SSID is configured as open with no encryption and without OWE. What is the primary link-layer confidentiality concern?
- A city explores Opportunistic Wireless Encryption (OWE) for an 'enhanced open' guest network. What is OWE's core purpose at awareness depth?
- A SOC analyst asks what RSN information in 802.11 beacons roughly communicates about a municipal BSS. Which answer is best?
- A school enables WPA3 Transition Mode so older devices can still join. What risk-awareness point should the security lead keep in mind?
- A municipal CISO asks what SAE changes versus classic WPA2-PSK handshake assumptions. Which statement is most accurate?
- A vendor proposes WPA3-Enterprise 192-bit mode for a high-security municipal wing. When is that suite most appropriate?
- A help desk ticket claims an SSID is 'Enterprise' solely because the AP shows WPA2-AES. What clarification separates cipher from AKM?
- A county wireless architect asks why GCMP appears beside CCMP in newer WPA3 literature. What is the awareness-level answer?
- A city attorney asks whether choosing a long, complex passphrase makes WEP acceptable for a remaining legacy SSID. What is the correct guidance?
- A stadium operations SSID uses one WPA2-Personal PSK across thousands of staff devices. What shared-secret risk should leadership understand?
- A library WLAN team compares Protected Management Frames (PMF / 802.11w) set to optional versus required. What is PMF's main purpose?
- A civic Wi-Fi standard bans WPA-only networks on city access points. What baseline should the wireless assessor affirm?
- A municipal SOC sees both PSK and 802.1X AKMs advertised on the same RSN-capable city SSID. How should the assessor interpret that mix?
- A clinic asks whether MAC filtering can substitute for WPA2 or WPA3 on the care-team SSID. What should the assessor conclude?
- A city guest design uses per-user PSK (PPSK-class) instead of one café-style passphrase. What contrast should the assessor highlight versus classic single PSK?
- An auditor reviewing a municipal RSN profile asks what 'group cipher' versus 'pairwise cipher' means at a high level. What is the correct contrast?
- A nonprofit enables WEP on the main lobby SSID because inventory scanners 'only support it.' What priority should the authorized assessor recommend?
- A municipal RF policy asks when VPN-over-Wi-Fi is still relevant for city staff. What guidance fits an OSWP-style encryption assessment?
- A student claims 'WPA2 is unbreakable' after reading about AES-CCMP. What nuance should the municipal mentor emphasize for Personal mode?
- A city compares CCMP and TKIP on a dual-mode park AP that still serves modern clients. Which cipher preference should the assessor recommend when interoperability allows?
- A parks AP lists 'Open System authentication' alongside WPA2 in the controller summary. What does that combination mean for confidentiality?
- A county asks if hiding the SSID plus enabling WEP equals defense-in-depth for staff Wi-Fi. What should the assessor answer?
- A hospital WLAN profile requires Protected Management Frames (PMF). Why does healthcare Wi-Fi care about that control?
- A city explores SAE-PK and related modern WPA3 Personal enhancements at awareness depth. What should planners understand?
- A procurement RFP for civic APs says only 'AES encryption' without specifying WPA2 versus WPA3. What should security reviewers demand?
- A SOC asks what happens to confidentiality assumptions if someone already knows the municipal PSK and can capture traffic. What is the sound high-level answer?
- A library wants guest Wi-Fi that encrypts traffic without distributing a shared password. Which design class should the assessor point to?
- A city still runs mixed WEP plus WPA on one BSS for 'compatibility.' What should the assessor conclude about that baseline?
- An intern asks whether WPA3-Enterprise always requires EAP-TLS on city staff Wi-Fi. What is the accurate clarification?
- A municipal standard cites WPA3 Transition Mode themes versus stricter WPA3-only behaviors. What should assessors verify in the field?
- A CISO asks for the simplest correct upgrade path from café-style WPA2-PSK city Wi-Fi to something safer for staff. What direction should the assessor recommend?