A CISO asks for the simplest correct upgrade path from café-style WPA2-PSK city Wi-Fi to something safer for staff. What direction should the assessor recommend?
Select an answer to reveal the explanation.
Short Explanation
Staff should not share the café pitcher password with every visitor. Give employees badge-based Enterprise 802.1X, and park guests on their own onboarded PSK or OWE SSID. Separate doors beat one sticky note for the whole city hall.
Full Explanation
WPA2-PSK café patterns share a single secret poorly suited to staff accountability and revoke. The straightforward upgrade is an Enterprise 802.1X staff SSID with appropriate EAP policy, while guest access remains on distinct Personal, PPSK, or OWE designs. Assessors should reject collapsing staff and guest trust into one long-lived shared passphrase.