certslothcertsloth
N10-009/Topic 06

CompTIA / Foundational

Wireless and Network Access Security

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Signal quality, channel plan and identity all matter.

Must remember

Wi-Fi shares airtime. Signal strength alone does not measure usable performance: interference, signal-to-noise ratio, channel contention, client capability and retries matter. In 2.4 GHz, 1/6/11 are the familiar nonoverlapping 20 MHz plan where permitted; 5/6 GHz offer more spectrum with region/device restrictions. Wider channels trade peak capacity for fewer independent channels and more overlap.

An SSID identifies a wireless network name; a BSSID identifies a basic service set/radio identity. Roaming requires compatible configuration and suitable coverage, not simply giving every AP the same name. Directional/omnidirectional antennas shape coverage; survey placement, walls, power and channel use.

WPA2/WPA3 protect Wi-Fi; enterprise modes use 802.1X/EAP with an authentication service such as RADIUS. Validate the server certificate and choose suitable EAP methods. Guest networks should have appropriate isolation and a controlled route to required services. A captive portal is not equivalent to strong link encryption or enterprise identity.

NAC can assess and authorize endpoints. Hardening includes management restrictions, secure firmware, disabled unused services, changed defaults, centralized logging and protected secrets. ACLs, firewall zones and URL/content filtering enforce different boundaries. TACACS+ is often chosen for network-device administrative AAA; RADIUS is common for network admission.

Threat cues: an evil twin imitates a trusted AP; ARP/DNS poisoning redirects traffic; MAC flooding pressures switch tables; VLAN hopping abuses weak trunk/native configurations; a rogue DHCP server supplies malicious addressing/gateway options. Segmentation, DHCP snooping, appropriate ARP inspection, port controls and user training address different paths.

Encryption, MFA and PKI complement physical locks/cameras. Treat IoT, BYOD and industrial systems according to their capabilities and risk, with controlled access rather than unconditional internal trust.

Choose under exam pressure

Requirement Choice and reason
Strong signal but poor throughput Inspect interference, channel contention, retries and client capabilities.
Enterprise user/device authentication 802.1X/EAP with validated RADIUS server identity.
Unmanaged guests Separate access and limited reachability.

Traps

  • Hidden SSIDs do not provide meaningful authentication.
  • Increasing transmit power can worsen interference or create asymmetric links.

Active recall

1. SSID versus BSSID?

SSID is the network name; BSSID identifies a particular basic service set.

2. Why validate the enterprise Wi-Fi server certificate?

To avoid sending credentials to an impersonated authentication service.

3. Does a captive portal encrypt radio traffic?

Not by itself.

4. What does DHCP snooping help establish?

Trusted DHCP-server-facing ports and bindings used to limit rogue DHCP behavior.

5. Why can maximum AP power be a poor fix?

Clients may not transmit back equally well and neighboring cells may interfere more.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.