A network technician is configuring wireless access for specialized barcode scanners in a distribution warehouse. The primary corporate wireless network relies on WPA3-Enterprise with 802.1X/RADIUS authentication using EAP-TLS client certificates. The new handheld scanners cannot store digital certificates or perform 802.1X authentication, but they fully support WPA3-Personal utilizing Simultaneous Authentication of Equals (SAE). Company policy requires network isolation for non-802.1X devices while maintaining the strongest possible wireless security controls without lowering the authentication requirements of the primary corporate network. Which of the following is the BEST solution for the technician to implement?
- Provision a new dedicated SSID configured with WPA3-Personal assigned to a segregated VLAN for the barcode scanners.Cevap
- BModify the primary corporate SSID to WPA3-Enterprise with TKIP protocol fallback to allow non-certificate devices to connect.
- CReconfigure the primary corporate SSID to WPA2-Personal so that all corporate laptops and warehouse scanners share a single passphrase.
- DSet up an open wireless network for the scanners and restrict access exclusively using MAC address filtering on the access points.
Cevap
Provision a new dedicated SSID configured with WPA3-Personal assigned to a segregated VLAN for the barcode scanners.
Deploying a dedicated SSID configured for WPA3-Personal (SAE) on a separate VLAN isolates non-802.1X handheld scanners from corporate assets while enforcing strong WPA3 pre-shared key encryption. This meets device compatibility requirements without weakening the 802.1X/EAP-TLS security on the primary corporate SSID.
Adım Adım Çözüm
Anahtar Kavram
WPA3-Personal vs Enterprise Coexistence and Network Segmentation
Tahmini Süre:2m 0s