A university WLAN still allows EAP-MD5 on an older staff profile. What awareness finding should the assessor raise?
Select an answer to reveal the explanation.
Short Explanation
EAP-MD5 on a campus staff SSID is museum tech on a live network. Old methods without solid protection do not belong on modern Enterprise WLANs—retire them.
Full Explanation
EAP-MD5 is a legacy authentication method lacking the protections expected on contemporary Enterprise WLANs. Allowing it on a university staff profile is an obsolete-method finding: migrate to stronger EAP methods with proper TLS and certificate validation. EAP-MD5 is not a WPA3-Enterprise 192-bit preference, does not replace Protected Management Frames, and is not mandated merely because RADIUS is present.