A city guest portal rides open/captive access while staff use WPA2-Enterprise on the same AP hardware. What multi-SSID security judgment matters most for assessment and design advice?
Select an answer to reveal the explanation.
Short Explanation
One box, two worlds: guest open portal and staff Enterprise can share AP silicon without sharing trust. The win is isolation so a lobby compromise does not stroll into staff VLANs. Do not force everyone onto the weakest model just because the AP is shared.
Full Explanation
Access points routinely advertise multiple SSIDs with independent security profiles—for example an open or captive-portal guest SSID alongside an 802.1X Enterprise staff SSID. Shared radio hardware does not require shared keys or inherited certificates. From an assessment and remediation perspective, the critical judgment is network isolation: guest compromise or portal abuse must not bridge into staff segments. Equalizing every SSID to the weakest model is not a sound design response.