TechKnowSurge
ISC2 CC 4.1 NIST 800-53 AC-18 CompTIA A+ Core 2 2.2 CompTIA Network+ 2.3 CompTIA A+ Core 2 2.9 Cisco CCST Cybersecurity 2.4 NIST 800-53 CM-6
InteractiveSecurityFree

Audit the Wi-Fi Setup

Read the setup sheet for TechKnowDJ's new access point and flag every choice that leaves the Wi-Fi open.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Wireless signals go out through the air, usually past the building's walls, and anyone with a wireless device can pick them up. So the traffic must be encrypted, and the access point must be set up with care. The protocols, weakest to strongest. Open: no credentials, no encryption, anyone can read the traffic. WEP (Wired Equivalent Privacy): meant to be as private as a wire, and broken; never use it. WPA, WPA2 and WPA3 (Wi-Fi Protected Access; the video says "wireless protection access"): each version is stronger than the last, so use the highest your devices support. Older devices are the usual reason to step down a version, and that is a real trade-off, not a mistake. How people connect. A pre-shared key is one password, shared in advance: once it leaks, anyone can use it, and it has to be changed whenever someone who knows it leaves. A captive portal opens a browser page where you log in or accept terms; it controls who gets on, but on its own it encrypts nothing, so a portal on an open network leaves the traffic readable. 802.1X sends each person's sign-in through the access point to an authentication server (RADIUS), with certificates or usernames and passwords, so everyone has their own credentials and one person can be removed without changing anything for the rest. Hardening the access point. Change the default SSID (a factory name tells an attacker the make and model) and the default admin credentials (they are published in the manual). Use the power settings and antennas to keep coverage where you need it, rather than out into the parking lot.

What you'll learn

Aligned to

ISC2 CC
4.1 Understand network security
NIST 800-53
AC-18 Wireless Access
CM-6 Configuration Settings
CompTIA A+ Core 2
2.2 Compare and contrast wireless security protocols and authentication methods.
2.9 Given a scenario, configure appropriate security settings on SOHO wireless and wired networks.
CompTIA Network+
2.3 Given a scenario, select and configure wireless devices and technologies.
Cisco CCST Cybersecurity
2.4 Set up a secure wireless SoHo network

Key terms

Wired Equivalent Privacy
WEP
Wired Equivalent Privacy is a deprecated IEEE 802.11 wireless security protocol that used RC4 encryption with a static shared key; it is considered cryptographically broken and must not be used in any modern environment.
Wi-Fi Protected Access
WPA
A wireless security certification program developed by the Wi-Fi Alliance to replace the vulnerable WEP standard, using TKIP for per-packet encryption and either 802.1X/RADIUS or a pre-shared key for authentication. WPA was a transitional standard, superseded by WPA2 which mandates AES/CCMP encryption.
Wi-Fi Protected Access 2
WPA2
An IEEE 802.11i-compliant wireless security certification that mandates AES-based CCMP encryption, providing substantially stronger data protection than WPA's TKIP. WPA2 supports both Personal mode (pre-shared key) and Enterprise mode (802.1X/RADIUS authentication).
Pre-Shared Key
PSK
A shared secret passphrase used for authentication in wireless networks and VPNs without requiring a dedicated authentication server. In WPA-Personal mode, the PSK is used to derive the Pairwise Master Key (PMK) for encrypting the wireless session.
Captive Portal
A browser-based authentication mechanism that requires users to log in through a web page before being granted access to a network.
802.1X
An IEEE standard for port-based network access control that requires devices to authenticate before gaining access to a wired or wireless network, using a supplicant, authenticator, and authentication server (typically RADIUS). It is the foundation of enterprise Wi-Fi security and wired port security using EAP methods.
Remote Authentication Dial-In User Service
RADIUS
RADIUS is a client-server networking protocol that provides centralized authentication, authorization, and accounting management for users connecting to network access points or VPN services.
Service Set Identifier
SSID
The network name broadcast by a wireless access point that clients use to identify and connect to a specific Wi-Fi network. SSIDs can be up to 32 characters long and are transmitted in beacon frames; networks may be configured to suppress SSID broadcasting for limited obscurity.
Default Credentials
Factory-set usernames and passwords that ship with network devices, applications, and services. Default credentials must be changed immediately upon deployment because they are publicly documented and frequently targeted by automated attackers.

Topics

Wi Fi Protected Access Pre Shared Key 802 1x Service Set Identifier Interactive Spot The Error

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →