A company replacing WPA2-PSK wants to cryptographically prevent clients from completing handshakes with rogue access points. Which implementation provides the strongest defense?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- ACorrect: EAP-TLS with strict certificate validation makes clients verify the network's server certificate, so a rogue AP without the trusted credential cannot complete authentication.
- BA captive portal authenticates users after they have already associated, so clients could still connect to a rogue AP that shows a lookalike portal.
- CProtected Management Frames stop forged deauthentication and disassociation frames, but they do not prove to a client that the access point itself is legitimate.
- DMAC filtering controls which clients the real AP accepts; it gives clients no way to verify an AP, and MAC addresses are trivially spoofed anyway.