A security engineer is implementing a new wireless network that must support a mix of corporate devices (laptops, phones) and guest devices. Corporate devices must use strong, certificate-based authentication, while guest devices require a simple, web-based authentication method. Both types of devices need to be placed in separate, isolated network segments with different access policies. Which combination of 802.1X and network access control features would best achieve these requirements?
- AEAP-TLS for corporate and a Captive Portal with Guest VLAN for guests.
- BWPA2-Enterprise with EAP-FAST for corporate and an open network with a disclaimer for guests.
- CWPA3-Personal for corporate and a pre-shared key (PSK) for guests.
- DPSK authentication for corporate and MAC filtering for guests.
Show answer & explanationAnswer & explanation
Correct answer: A. EAP-TLS for corporate and a Captive Portal with Guest VLAN for guests.
EAP-TLS provides strong, certificate-based authentication required for corporate devices. A Captive Portal with a Guest VLAN offers a simple web-based authentication for guests and places them into an isolated segment, fulfilling all requirements. PSK and MAC filtering are less secure. EAP-FAST is certificate-less but still robust, while an open network is insecure. WPA3-Personal and PSK are not suitable for enterprise certificate-based corporate access or simple guest web authentication with isolation.
Why the other options are wrong
- B. EAP-FAST is a robust EAP method but not explicitly certificate-based as requested, and an open network for guests is highly insecure.
- C. WPA3-Personal and PSK are not suitable for enterprise certificate-based corporate authentication and do not typically integrate with easy web-based guest access with isolation.
- D. PSK is less secure than certificate-based authentication for corporate, and MAC filtering is easily bypassed and unscalable for guests.
Dual-Mode Wireless Access (EAP-TLS & Captive Portal)
A wireless network design that uses different authentication methods for different user groups (e.g., EAP-TLS for corporate devices requiring strong certificate-based security, and a Captive Portal for guests needing simple web-based access with segmentation).
- Accommodates diverse security needs.
- Provides strong corporate device authentication.
- Offers easy and isolated guest access.
Memory trick: Corporate gets a key, guests fill out a form, both stay in their own rooms.