An IT security consultant is upgrading the wireless infrastructure for a regional healthcare clinic. To ensure compliance with patient data privacy regulations, the new network must provide centralized authentication using unique user credentials rather than a shared passphrase, while enforcing mutual authentication to protect against rogue access point attacks. Which of the following security controls and authentication mechanisms should the consultant implement? (Select TWO.)
- WPA3-Enterprise operating with an 802.1X RADIUS serverAnswer
- EAP-TLS authentication utilizing client and server digital certificatesAnswer
- CWPA2-Personal configured with Simultaneous Authentication of Equals (SAE)
- DMAC address filtering combined with disabling SSID broadcast
Answer
WPA3-Enterprise operating with an 802.1X RADIUS server, and EAP-TLS authentication utilizing client and server digital certificates.
WPA3-Enterprise combined with an 802.1X RADIUS server allows central user management and individual account authentication. Implementing EAP-TLS satisfies the mutual authentication requirement because both the server and client validate each other's digital certificates before establishing the encrypted session.
Step-by-Step Solution
Key Concept
Enterprise Wireless Authentication and Mutual Security Controls
Estimated Time:1m 30s