Rogue APs pose a significant risk and should be detected and mitigated automatically.
D. A properly configured Wireless Intrusion Prevention System (WIPS) can detect unauthorized APs and prevent client associations to them in real time.
Incorrect:
A. While WPA2-Enterprise adds client-level protection, it does not detect rogue APs.
B. Hiding SSIDs is ineffective—SSIDs are still discoverable in management frames.
C. Manual scans are labor-intensive and impractical for ongoing monitoring.
E. Port security controls wired threats but cannot detect rogue APs using wireless signals.
[References:, , CWSP-208 Study Guide, Chapter 6 (Wireless Intrusion Prevention Systems), , CWNP Rogue Detection Strategies, ]
Submit