A clinic IoT SSID uses the device serial number printed on the badge as its WPA2-PSK. How should an assessor classify that choice?
Select an answer to reveal the explanation.
Short Explanation
If the password is etched on the gadget for anyone walking by, it is not a secret—it is a name tag. Serial-as-PSK fails entropy because recon can read it. Treat that as discoverable credential failure, not clever provisioning.
Full Explanation
Passphrases taken from chassis serials, sticker defaults, or other physically observable labels give nearby attackers a short path from recon to a working PSK candidate. Uniqueness of a serial does not equal secrecy once the label is readable. Hiding the SSID does not remediate a public PSK, and the issue remains a Personal-mode entropy failure rather than an Enterprise PEAP problem. Assessments should recommend high-entropy secrets not derived from public device identity.