A county mandates EAP-TLS for staff laptops on the corporate SSID. What strength class does that requirement target?
Select an answer to reveal the explanation.
Short Explanation
Certificates on both sides beat "password inside a PEAP burrito." EAP-TLS is the staff laptop showing a badge and checking the building's badge too. Done right, there is no MSCHAPv2 souvenir for attackers.
Full Explanation
EAP-TLS authenticates with X.509 certificates for the client and the server, eliminating password inner methods such as MSCHAPv2 when deployment and lifecycle are sound. It still relies on 802.1X and an authentication server; it does not fall back to a WLAN PSK model. Guest open portals are a different design. Proper certificate management is part of realizing that strength class.