A PEAP deployment for county staff omits the validate server certificate option on endpoints. What misconfiguration class does that create?
Select an answer to reveal the explanation.
Short Explanation
Unchecked 'validate server certificate' is a welcome mat for a look-alike PEAP twin. That misconfig class makes credential harvesting much easier—not SAE mode, WEP wrapping, or free anonymity.
Full Explanation
When PEAP clients skip server certificate validation, they will establish the TLS tunnel to a rogue authenticator that presents any certificate. That misconfiguration class materially increases evil-twin credential harvesting risk for password-based inner methods. It does not convert the network to WPA3-SAE Personal, wrap MSCHAPv2 in WEP, or by itself configure anonymous outer identity privacy.