A municipal laptop Wi-Fi profile uses incorrect outer identity privacy settings during EAP. What identity-privacy awareness should IT apply?
Select an answer to reveal the explanation.
Short Explanation
Wrong outer-identity privacy is a chatty name tag on the air. Anonymous outer identities, when supported, cut username leakage during EAP—privacy settings do matter.
Full Explanation
Many EAP methods can send an outer identity before the inner authentication completes. Configuring an anonymous or privacy-preserving outer identity (when the deployment supports it) reduces passive username leakage. Outer identities are transmitted in relevant flows, must not be set to the password, and privacy settings do not disable server certificate validation by design.