A clinic staff SSID uses PEAP with MSCHAPv2 as the inner method. What weakness class should assessors recognize at concept level?
Select an answer to reveal the explanation.
Short Explanation
PEAP wraps the chat, but MSCHAPv2 inside still carries old password baggage. If that inner material leaks in the wrong setting, trouble follows. Think "tunnel helps"—not "tunnel equals smart cards."
Full Explanation
PEAP commonly protects an inner MSCHAPv2 password exchange with a TLS tunnel to the authentication server. The inner method still inherits MSCHAPv2 weakness classes if an attacker can obtain relevant challenge/response material, especially when clients omit proper server certificate checks. That profile is not equivalent to EAP-TLS mutual certificate authentication. Assessments should discuss method risk without providing exploit recipes.