An auditor wants proof that municipal staff cannot join a rogue AP broadcasting the corporate SSID. What assurance approach fits?
Select an answer to reveal the explanation.
Short Explanation
Want proof staff will not wander into a twin? Purple-team it under RoE: authorized evil-twin tests show whether cert checks actually stick. Hiding the SSID is not that proof.
Full Explanation
Assurance that endpoints refuse rogue Enterprise APs comes from controlled testing and configuration evidence—especially whether clients validate EAP server certificates. Authorized evil-twin exercises under clear RoE reveal real-world behavior better than SSID hiding, suppressed RADIUS logs, or assuming a WPA3 badge alone blocks unauthorized BSSIDs.