A city segments the staff Enterprise SSID from an open guest network. What architecture hygiene does that separation primarily enforce?
Select an answer to reveal the explanation.
Short Explanation
Staff Enterprise and open guest should live on different doors and different hallways—separate SSIDs and VLANs with different trust. Do not mash them into one PSK or one AD group story.
Full Explanation
Architectural hygiene for municipal Wi-Fi keeps authenticated staff 802.1X SSIDs separate from open or captive-portal guest networks, typically with distinct VLANs and firewall policies. Trust levels differ, so shared credentials or merged directory group inheritance across those paths undermine the design. Guests should not be forced into staff PEAP merely to receive DHCP, and a single PSK should not authorize both populations.