An assessor documents required client trust-store settings for municipal Enterprise laptops. What hardening guidance belongs in that note?
Select an answer to reveal the explanation.
Short Explanation
Hardening means laptops only trust the real RADIUS cert—or a pinned issuer—and reject strangers. 'Trust anyone for speed' is how evil twins win.
Full Explanation
Endpoint trust-store and Wi-Fi profile settings should require validation of the expected RADIUS/EAP server certificate and reject untrusted presenters. That control is central to resisting Enterprise evil twins. Guidance that tells clients to trust any cert, disable checks for convenience, or expose the RADIUS shared secret to end users undermines the control plane between authenticator and AAA.