Question 1
A financial services company is deploying a new 802.11ax network and must comply with PCI-DSS 4.0 requirements. The security architect is designing the authentication mechanism for corporate-owned laptops. The primary requirements are to use device-specific credentials, prevent credential sharing, and ensure the strongest possible cryptographic protection. Which authentication and EAP method combination should be implemented to meet these requirements?
Answer and explanation
Correct answer: C
WPA3-Enterprise with EAP-TLS is the strongest combination. EAP-TLS uses client-side and server-side certificates for mutual authentication, providing device-specific credentials that cannot be easily shared. This meets the stringent requirements of PCI-DSS. WPA3-Personal uses a shared key, which violates the device-specific credential requirement. EAP-PEAP uses a server-side certificate but relies on username/password credentials inside the tunnel, which are weaker than certificates. OWE is designed for unauthenticated encryption on open networks, not for corporate authentication.