A clinic asks whether MAC filtering can substitute for WPA2 or WPA3 on the care-team SSID. What should the assessor conclude?
Select an answer to reveal the explanation.
Short Explanation
MAC filtering is like checking jackets at the door by color—anyone can grab a matching coat. It does not encrypt the air and spoofing is trivial. Clinics still need real WPA2/WPA3 crypto, not an allow-list costume party.
Full Explanation
Address filtering operates on spoofable Layer-2 identifiers and does not provide cryptographic confidentiality or mutual authentication. Strong WLAN security depends on modern AKMs and ciphers such as WPA2-CCMP or WPA3, not on MAC allow-lists. Assessors should reject MAC filtering presented as a substitute for encryption on healthcare or other sensitive SSIDs.