Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsMedium

A network technician is setting up a new wireless access point (WAP) for a small office. To enhance security, the technician decides to configure the WAP to only allow devices with specific hardware addresses to connect to the network. Which security feature is the technician implementing?

  1. ASSID broadcast disable
  2. BPort security
  3. CMAC address filtering
  4. DWPA3 encryption
Show answer & explanation

Correct answer: C. MAC address filtering

MAC address filtering is a security feature that allows or denies network access to devices based on their unique Media Access Control (MAC) address. By configuring the WAP to only allow specific hardware addresses (MAC addresses), the technician is implementing MAC address filtering.

Why the other options are wrong

  • A. Disabling SSID broadcast hides the network name but doesn't prevent connection from unauthorized devices if the SSID is known.
  • B. Port security is typically implemented on switches to restrict devices on physical switch ports, not for wireless access points in this context.
  • D. WPA3 encryption protects data transmission, but doesn't control which devices can connect based on hardware address.

MAC Address Filtering

A security method that controls network access by allowing or denying devices based on their unique Media Access Control (MAC) address.

  • Uses a whitelist or blacklist of MAC addresses.
  • Offers a basic layer of network access control.
  • Can be bypassed by MAC spoofing, so not a standalone solution.

Memory trick: Wireless security is like locking your Wi-Fi door.

More Security Fundamentals questions