A city uses a unique 20-character random PSK on a staff IoT SSID. What residual risk class remains even when offline guessing looks impractical?
Select an answer to reveal the explanation.
Short Explanation
A long random PSK is a tough lock, but it is still one spare key hanging on a shared hook. Staff, vendors, and sticky notes can still spread it, and rotation still matters. Offline toughness is not the same as perfect Personal-network hygiene.
Full Explanation
High-entropy PSKs substantially reduce the practicality of offline dictionary recovery within typical assessment windows. They do not remove the operational properties of a shared secret: distribution to devices and people, difficult rotation, and broad impact if disclosed. Personal mode also does not become Enterprise 802.1X merely because the passphrase is long. Residual risk reporting should separate crypto strength from shared-PSK lifecycle concerns.