About this interactive
Wireless signals go out through the air, usually past the building's walls, and anyone with a wireless device can pick them up. So the traffic must be encrypted, and the access point must be set up with care.
The protocols, weakest to strongest. Open: no credentials, no encryption, anyone can read the traffic. WEP (Wired Equivalent Privacy): meant to be as private as a wire, and broken; never use it. WPA, WPA2 and WPA3 (Wi-Fi Protected Access; the video says "wireless protection access"): each version is stronger than the last, so use the highest your devices support. Older devices are the usual reason to step down a version, and that is a real trade-off, not a mistake.
How people connect. A pre-shared key is one password, shared in advance: once it leaks, anyone can use it, and it has to be changed whenever someone who knows it leaves. A captive portal opens a browser page where you log in or accept terms; it controls who gets on, but on its own it encrypts nothing, so a portal on an open network leaves the traffic readable. 802.1X sends each person's sign-in through the access point to an authentication server (RADIUS), with certificates or usernames and passwords, so everyone has their own credentials and one person can be removed without changing anything for the rest.
Hardening the access point. Change the default SSID (a factory name tells an attacker the make and model) and the default admin credentials (they are published in the manual). Use the power settings and antennas to keep coverage where you need it, rather than out into the parking lot.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →