Courseiva
Network Security →hardMultiple Select

ISC2 CC Network Security Practice Question

A security architect is designing defenses against on-path attacks on a corporate wireless network where employees connect to internal applications. Which two controls most directly protect the confidentiality and integrity of employee traffic against an attacker who can observe or modify wireless frames? (Choose two.)

⚠ Common exam trap

The trap here is treating visibility or obscurity controls, such as wireless intrusion detection or hidden SSIDs, as if they provided cryptographic protection of traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Requiring TLS for all internal application traffic between clients and servers.

Protecting against an on-path attacker requires cryptography at both the wireless link and the application layer. WPA3-Enterprise with protected management frames secures the radio hop and prevents management-frame manipulation, while TLS secures application data end to end. Monitoring, SSID hiding, and MAC filtering may add visibility or friction but do not encrypt or integrity-protect the traffic itself, so they do not directly meet the stated goal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploying a wireless intrusion detection system to alert on rogue access points.

    Why it's wrong here

    A wireless intrusion detection system identifies rogue access points and suspicious wireless activity, which improves visibility and response, but it is a monitoring control that does not itself encrypt or integrity-protect employee traffic. An on-path attacker could still read or modify frames while alerts fire, so it does not directly satisfy the confidentiality and integrity requirement.

  • ✓

    Requiring TLS for all internal application traffic between clients and servers.

    Why this is correct

    TLS encrypts and integrity-protects application data end to end between the client and the server, so even if an attacker captures or manipulates wireless frames, the payload remains confidential and tampering is detected. This complements link-layer protections by securing the traffic above the wireless hop, directly addressing on-path confidentiality and integrity.

  • ✗

    Implementing MAC address filtering to admit only known corporate devices.

    Why it's wrong here

    MAC address filtering restricts which devices associate based on a spoofable identifier, so it provides no cryptographic protection for traffic and can be bypassed by an attacker cloning an approved address. It does not prevent an on-path attacker from reading or modifying wireless frames, leaving confidentiality and integrity unprotected.

  • ✓

    Enforcing WPA3-Enterprise with protected management frames on the wireless infrastructure.

    Why this is correct

    WPA3-Enterprise provides strong per-session encryption and mutual authentication, so an observer cannot read or silently alter the wireless frames, and protected management frames prevent spoofed deauthentication and disassociation attacks used to force clients onto attacker-controlled channels. Together they directly defend confidentiality and integrity against an on-path attacker on the wireless segment.

  • ✗

    Disabling SSID broadcast to make the corporate network harder to find.

    Why it's wrong here

    Hiding the SSID is a weak obscurity measure because the network name is still exposed in management and probe frames, and it does not encrypt or authenticate traffic in any way. An attacker who can observe wireless frames can still capture or tamper with them, so this control does not protect confidentiality or integrity.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.