A small business owner wants to replace their old wireless router because guests have been using the network to access inappropriate content. The owner wants to isolate guest traffic from the main business network and enforce content filtering. Which combination of wireless security and features should the technician recommend?
Trap 1: WPA3-Personal with MAC address filtering.
MAC address filtering restricts which known devices associate, and WPA3-Personal secures the link, but neither creates a separate guest network nor filters content. A guest SSID with client isolation and a content-filtering service is what the scenario requires; MAC filtering is for whitelisting specific hardware.
Trap 2: WPA2-Enterprise with a RADIUS server and no guest network.
WPA2-Enterprise with RADIUS authenticates individual users via 802.1X, which is the right choice for corporate staff access, but omitting a guest network leaves visitors on the business LAN with no isolation or filtering. The scenario needs a segregated guest SSID with content filtering.
Trap 3: WEP encryption with a hidden SSID.
WEP is cryptographically broken and a hidden SSID is trivially discovered, so neither isolates guest traffic nor filters content. WEP suits only legacy hardware compatibility; the requirement here is a separate guest network with client isolation and content filtering.
- A
WPA3-Personal with MAC address filtering.
Why it fails: MAC address filtering restricts which known devices associate, and WPA3-Personal secures the link, but neither creates a separate guest network nor filters content. A guest SSID with client isolation and a content-filtering service is what the scenario requires; MAC filtering is for whitelisting specific hardware.
- B
WPA2-PSK with a guest network enabled and content filtering via OpenDNS.
WPA2-PSK secures the wireless link, while a guest network provides a separate SSID and VLAN, isolating visitor traffic from business resources. OpenDNS enforces content filtering at the DNS layer, satisfying the requirement to block inappropriate content without extra hardware.
- C
WPA2-Enterprise with a RADIUS server and no guest network.
Why it fails: WPA2-Enterprise with RADIUS authenticates individual users via 802.1X, which is the right choice for corporate staff access, but omitting a guest network leaves visitors on the business LAN with no isolation or filtering. The scenario needs a segregated guest SSID with content filtering.
- D
WEP encryption with a hidden SSID.
Why it fails: WEP is cryptographically broken and a hidden SSID is trivially discovered, so neither isolates guest traffic nor filters content. WEP suits only legacy hardware compatibility; the requirement here is a separate guest network with client isolation and content filtering.