10. An organization's network has been the target of several cyberattacks. Which strategy should the organization use for Wi-Fi hardening?

Answer: D

Explanation:

Disabling ESSID broadcasting enhances Wi-Fi security.

Disabling ESSID broadcasting prevents the wireless network's name from being publicly visible, making it less susceptible to unauthorized access and attacks.

A) Implement wired equivalent privacy (WEP)

WEP is an outdated security protocol with known vulnerabilities that can be easily exploited by attackers. Therefore, implementing WEP would not effectively harden Wi-Fi security and could expose the network to further risks.

B) Add more access points

While adding more access points can improve coverage, it does not inherently enhance security. In fact, it may increase the attack surface if not properly secured, making the network more vulnerable to unauthorized access.

C) Trust local hosts by default

Trusting local hosts by default is a risky strategy that can lead to security breaches. This approach assumes all local devices are secure, which is often not the case, especially in environments where devices may be compromised.

D) Disable ESSID broadcasting

Disabling ESSID broadcasting is a proactive measure that reduces the visibility of the network to potential attackers. By making the network less detectable, it discourages unauthorized access attempts and enhances overall security.

Conclusion

Disabling ESSID broadcasting is the most effective strategy for Wi-Fi hardening among the options provided, as it minimizes the network's exposure to potential threats. Other options either introduce vulnerabilities or do not significantly contribute to enhancing security, making them less suitable for protecting against cyberattacks.