A county asks if hiding the SSID plus enabling WEP equals defense-in-depth for staff Wi-Fi. What should the assessor answer?
Select an answer to reveal the explanation.
Short Explanation
Hiding the network name is pulling the curtains, and WEP is a cardboard lock. Neither stacks into real defense-in-depth. County staff need modern AKM and ciphers, not security-by-embarrassment.
Full Explanation
SSID cloaking does not stop discovery by capable observers and fails as a primary control. WEP is obsolete cryptography and cannot anchor a defense-in-depth story for county staff WLANs. Effective protection requires contemporary authentication and key-management suites such as WPA2/WPA3 with appropriate Enterprise or Personal design—not obscurity paired with broken ciphers.