A county compares password-spray risk on Enterprise Wi-Fi usernames discovered via EAP. What chained risk should the brief note?
Select an answer to reveal the explanation.
Short Explanation
Usernames leaking from EAP are breadcrumbs to the directory door. If nobody watches, spray classes may follow—call that chained risk, not a free PSK or a WPS-only problem.
Full Explanation
Identities observed during EAP negotiation can enrich username lists for password spraying or stuffing against municipal directories and VPN portals. That is a chained risk spanning wireless recon and identity attacks, warranting monitoring and identity privacy controls where supported. Seeing an EAP identity does not disclose the PSK, imply WPS PIN constraints, or guarantee daily username rotation.