ExamRange

CND (312-38) Network Defense Simulation

Master wireless network hardening. Learn to identify and correct misconfigurations that leave corporate infrastructure vulnerable to unauthorized access and wardriving attacks.

Network Scenario

You are conducting a security audit of a newly acquired subsidiary's wireless infrastructure. During a physical site survey of the perimeter, you run a passive RF scan using Kismet. The results show several Access Points (APs) broadcasting default configurations. Upon logging into the Wireless LAN Controller (WLC), you discover that the previous IT administration left the wireless networks in a highly vulnerable state, increasing the risk of unauthorized access and lateral movement into the corporate intranet. You must identify the correct best practice to begin hardening the wireless network.

Traffic & Logs

[WLC-01] # show wlan 1 detail WLAN Identifier: 1 Profile Name: Corp_Main Network Name (SSID): default Broadcast SSID: Enabled Remote Management (HTTP/HTTPS/SSH): Enabled (WAN/LAN) Client Isolation: Disabled Intranet Access: Unrestricted (No ACL applied) [SECURITY AUDIT SCRIPT OUTPUT] WARNING: AP is broadcasting default SSID. Vulnerable to dictionary mapping. WARNING: Remote administrative login enabled on external interfaces. WARNING: Missing packet filtering between Wireless subnet and internal VLANs.

Question

Which of the following is a best practice for wireless network security?