ISC2 CC Network Security Practice Question
A security architect is designing defenses against on-path attacks on a corporate wireless network where employees connect to internal applications. Which two controls most directly protect the confidentiality and integrity of employee traffic against an attacker who can observe or modify wireless frames? (Choose two.)
⚠ Common exam trap
The trap here is treating visibility or obscurity controls, such as wireless intrusion detection or hidden SSIDs, as if they provided cryptographic protection of traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Requiring TLS for all internal application traffic between clients and servers.
Protecting against an on-path attacker requires cryptography at both the wireless link and the application layer. WPA3-Enterprise with protected management frames secures the radio hop and prevents management-frame manipulation, while TLS secures application data end to end. Monitoring, SSID hiding, and MAC filtering may add visibility or friction but do not encrypt or integrity-protect the traffic itself, so they do not directly meet the stated goal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploying a wireless intrusion detection system to alert on rogue access points.
Why it's wrong here
A wireless intrusion detection system identifies rogue access points and suspicious wireless activity, which improves visibility and response, but it is a monitoring control that does not itself encrypt or integrity-protect employee traffic. An on-path attacker could still read or modify frames while alerts fire, so it does not directly satisfy the confidentiality and integrity requirement.
- ✓
Requiring TLS for all internal application traffic between clients and servers.
Why this is correct
TLS encrypts and integrity-protects application data end to end between the client and the server, so even if an attacker captures or manipulates wireless frames, the payload remains confidential and tampering is detected. This complements link-layer protections by securing the traffic above the wireless hop, directly addressing on-path confidentiality and integrity.
- ✗
Implementing MAC address filtering to admit only known corporate devices.
Why it's wrong here
MAC address filtering restricts which devices associate based on a spoofable identifier, so it provides no cryptographic protection for traffic and can be bypassed by an attacker cloning an approved address. It does not prevent an on-path attacker from reading or modifying wireless frames, leaving confidentiality and integrity unprotected.
- ✓
Enforcing WPA3-Enterprise with protected management frames on the wireless infrastructure.
Why this is correct
WPA3-Enterprise provides strong per-session encryption and mutual authentication, so an observer cannot read or silently alter the wireless frames, and protected management frames prevent spoofed deauthentication and disassociation attacks used to force clients onto attacker-controlled channels. Together they directly defend confidentiality and integrity against an on-path attacker on the wireless segment.
- ✗
Disabling SSID broadcast to make the corporate network harder to find.
Why it's wrong here
Hiding the SSID is a weak obscurity measure because the network name is still exposed in management and probe frames, and it does not encrypt or authenticate traffic in any way. An attacker who can observe wireless frames can still capture or tamper with them, so this control does not protect confidentiality or integrity.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
WPA3
WPA3 is the latest security standard for Wi-Fi networks, providing stronger encryption and protection against password guessing attacks compared to its predecessor WPA2.
Key term
Confidentiality
Confidentiality means keeping sensitive information secret and accessible only to authorized people or systems.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.