A sales representative using a company-issued mobile device reports that while working at a remote customer location, their smartphone automatically connected to an open Wi-Fi network that shared the exact SSID of the company's secure corporate network. Subsequently, the user received SSL/TLS certificate warnings whenever opening internal enterprise applications. Which of the following Mobile Device Management (MDM) security policies should be enforced to BEST prevent devices from automatically joining unauthorized networks broadcasting corporate SSIDs?
- Configure the Wi-Fi configuration profile to disable automatic connection to open Wi-Fi networks and mandate 802.1X server certificate verification.Answer
- BContact the cellular service provider to reset the SIM card provisioning profile and re-issue the mobile data plan.
- CDowngrade the primary corporate wireless network authentication setting from WPA3-Enterprise to WPA2-Personal (PSK).
- DRevoke device administrator privileges for all installed third-party mobile web browser applications.
Answer
Configure the Wi-Fi configuration profile to disable automatic connection to open Wi-Fi networks and mandate 802.1X server certificate verification.
The correct option addresses the root cause of an Evil Twin rogue access point attack. By deploying an MDM Wi-Fi profile that disables automatic connection to open networks and enforces 802.1X RADIUS server certificate validation, the mobile OS will refuse to join unencrypted networks broadcasting the corporate SSID and will verify the authentic server certificate before exchanging credentials.
Step-by-Step Solution
Key Concept
Rogue Access Point (Evil Twin) Prevention via MDM Wi-Fi Profiles