QuestionQ5

Network security

A network engineer is configuring guest access on a Wi-Fi network. Following a recent network analysis, the engineer found that a user could connect to the guest network and attack the corporate network because both networks use the same VLAN. Which of the following should the engineer do to prevent a similar attack from occurring?

Explanation

Layer 2 client isolation prevents direct client-to-client communication on the wireless Layer 2 network, reducing lateral attacks by guest devices against other endpoints on the shared VLAN. MAC filtering, a wireless password, and captive-portal registration restrict or identify access but do not stop an already connected guest from communicating with corporate devices on the same VLAN.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!