Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementMedium

A network architect is designing a secure guest Wi-Fi solution for a corporate environment. The solution must ensure that guest users can access the internet but are strictly isolated from the internal corporate network and cannot communicate with each other. Which combination of technologies would best achieve these requirements?

  1. AWPA3-Personal with a shared pre-shared key
  2. BSeparate VLAN for guests, Client Isolation, and a dedicated Firewall policy
  3. COpen Wi-Fi with MAC address filtering
  4. DWPA2-Enterprise with a single flat network
Show answer & explanation

Correct answer: B. Separate VLAN for guests, Client Isolation, and a dedicated Firewall policy

A separate VLAN isolates guest traffic from the corporate network. Client isolation prevents guests from communicating with each other on the same SSID. A dedicated firewall policy then controls internet access while blocking access to internal resources, fulfilling all requirements.

Why the other options are wrong

  • A. WPA3-Personal is for home use; a shared PSK does not provide per-user isolation or prevent guest-to-guest communication.
  • C. Open Wi-Fi is insecure, and MAC address filtering is easily bypassed and doesn't prevent client-to-client communication.
  • D. WPA2-Enterprise provides strong authentication but a single flat network does not isolate guests from the internal network.

Guest Wi-Fi Isolation

A security design principle for wireless networks that ensures guest users are segmented from the corporate network and often from each other, while still providing internet access.

  • Prevents unauthorized access to internal resources.
  • Reduces the attack surface from untrusted devices.
  • Typically involves VLANs, client isolation, and firewall rules.

Memory trick: Guests get their own isolated, firewalled lane to the internet.

More Visibility and Enforcement questions