Municipal IT asks for a map of guest-Wi-Fi SSIDs around City Hall. Which PORP-appropriate method should the analyst use?
Select an answer to reveal the explanation.
Short Explanation
Wireless OSINT here is looking at the public map, not picking the lock. Pull the observed SSIDs and pins from a wardriving-class dataset and date the pull. Handshake hunts, deauths, and fake APs belong to a different cert.
Full Explanation
PORP wireless work is observational: public datasets that record SSIDs, BSSIDs, and approximate locations (WiGLE-class corpora) are in scope for mapping guest networks around a civic building. Key recovery, deauthentication, and rogue-AP operations are offensive wireless techniques and are out of PORP. The report should cite the dataset, query area, and observation dates. Ownership of an SSID is not proven by a map pin alone.