16. Which strategy should the organization use for Wi-Fi hardening?
Answer: A
Disabling ESSID broadcasting is the recommended strategy for Wi-Fi hardening.
Disabling ESSID broadcasting helps to enhance the security of Wi-Fi networks by preventing the network's name from being publicly visible, thereby reducing the chances of unauthorized access.
A) Disable ESSID broadcasting
This option is correct as it effectively hides the network from casual users and potential attackers. By disabling ESSID broadcasting, the organization can make it less obvious that the network exists, which serves as an initial layer of defense against unauthorized access attempts.
B) Implement wired equivalent privacy (WEP)
This option is incorrect because WEP is an outdated and insecure protocol that is easily compromised. Relying on WEP for encryption does not provide adequate protection for the network, and modern alternatives, such as WPA2 or WPA3, should be utilized instead.
C) Trust local hosts by default
This option is also incorrect as it poses a significant security risk. Trusting local hosts by default can lead to vulnerabilities, as it may allow unauthorized devices to connect to the network without proper verification, undermining the organization's security posture.
D) Add more access points
This option is incorrect as simply adding more access points does not inherently enhance security. While it may improve coverage, it can also increase the attack surface and does not address the core security issues that Wi-Fi hardening aims to resolve.
Conclusion
Disabling ESSID broadcasting is the most effective strategy for Wi-Fi hardening as it minimizes visibility to potential attackers. In contrast, the other options either rely on outdated technology, create security vulnerabilities, or do not address the fundamental need for network protection. Therefore, option A is the most appropriate choice for enhancing Wi-Fi security.