Skip to main content

Unit 3 · Topic 3.2

3.2 Protecting Networks: Managerial Controls and Wireless Security

Managerial controls set the minimum rules every router, switch, VPN and wireless network must follow, and wireless settings put those rules into practice. This topic covers the four network policies the course names and how to configure Wi-Fi so outsiders can't easily find it, join it or read it.

Key terms

  • router and switch security policy
  • port security
  • MAC filtering
  • split tunneling
  • beacon frame
  • WPA3

Router and switch security policies

A router security policy sets the minimum configuration for every router on the network, and a switch security policy does the same for switches. Typical requirements:

  • Routers and switches: no local user accounts. All logins go through an approved central authentication server, so access can be managed and revoked in one place.
  • Routers: unnecessary services turned off, such as Telnet, an old remote-login service that sends everything, including passwords, unencrypted.
  • Routers: a firewall, either built in or as a separate device.
  • Switches: port security turned on, which limits which and how many devices can use each port.
  • Switches: MAC filtering, which allows only approved MAC addresses.

VPN and wireless security policies

A VPN policy sets the rules for employees who connect to the internal network from outside. It may list which roles are allowed to use the VPN, set authentication requirements (such as a public/private key system or MFA) and ban split tunneling. In split tunneling, also called dual tunneling, only some of a device's traffic goes through the VPN while the rest goes straight to the internet. That leaves the device connected to the open internet and the company network at the same time, and the company can't see or filter the traffic that skips the VPN.

A wireless security policy may require users to authenticate through EAP (extensible authentication protocol) connected to an approved authentication server, require all wireless traffic to be encrypted with AES at a minimum key length, and require beacon frames to be turned off.

Configuring wireless security

  • Disable beacon frame broadcasting. Access points normally announce their network name and settings several times a second. Turning this off makes the network harder to find and learn about. It's a speed bump, not a lock: devices that join still send the name, so a determined adversary can find it.
  • Control direction and signal strength. Position access points and turn down their power so the signal covers the space it's meant to and doesn't spill into the parking lot or street.
  • Use strong encryption so captured wireless frames can't be read. WEP, WPS and the original WPA have known vulnerabilities and are insecure. (WPS, Wi-Fi Protected Setup, is really a quick-connect feature rather than encryption, but its PIN method is easy to break, so the course lists it with the others.) The course framework (fall 2026) names WPA3 as the strongest option. Check the current recommendation in future years, since standards change.
  • Turn on MAC filtering so only approved devices can join, and require users to authenticate. MAC filtering alone can be beaten by MAC spoofing, which is why it's one layer among several.

Worked examples

Try each one yourself first, then open the solution.

  1. Example 1

    Checking a configuration against policy

    Granite Insurance's wireless policy requires authentication through the company's authentication server, AES encryption and disabled beacon frames. An audit of one access point finds: security mode WPA with a shared password; SSID broadcast on; transmit power at maximum, and the signal reaches the street. List each problem and the fix.

    Show the solution
    1. Step 1: Security mode: the original WPA is insecure, and a shared password isn't per-user authentication through the company server. Fix: switch to WPA3 (AES-based) with EAP authentication to the approved server.
    2. Step 2: SSID broadcast on: the policy requires beacon frames to be disabled. Fix: turn off beacon broadcasting.
    3. Step 3: Signal reaching the street: not a written policy item here, but it lets outsiders pick up the network. Fix: lower the transmit power and adjust the antenna direction so coverage stays inside the building.

    Answer: Replace WPA and the shared password with WPA3 plus EAP authentication to the approved server, disable beacon frames, and reduce the power and adjust the direction so the signal stays inside.

  2. Example 2

    Why ban split tunneling?

    A sales rep wants split tunneling turned on so video calls don't go through the slow company VPN. The VPN policy forbids it. Explain the security reason.

    Show the solution
    1. Step 1: Describe split tunneling: some traffic goes through the encrypted VPN to the company, and the rest goes straight to the internet.
    2. Step 2: Identify the risk: the laptop is on the open internet and inside the company network at once, so malware or an adversary reaching the laptop over the direct path has a route into the internal network.
    3. Step 3: Add the visibility problem: traffic that skips the VPN also skips the company's firewalls and monitoring.

    Answer: With split tunneling, the laptop is connected to the open internet and the company network at the same time, and the direct traffic bypasses company firewalls and monitoring, so a compromise on the internet side could reach the internal network unnoticed.

Common mistakes

  • Thinking hiding the SSID or MAC filtering makes a network secure by itself. Both slow adversaries down, but they can be worked around; strong encryption and authentication do the real work.
  • Calling WPA (the original) secure because it's newer than WEP. The course lists WEP, WPS and original WPA as insecure; WPA3 is the strongest.
  • Confusing a policy with a configuration. The policy is the written rule (managerial); the settings on the device carry it out (technical).
  • Forgetting why Telnet is disabled: it sends logins and data unencrypted.

On the exam

  • You may be asked which policy item addresses a described risk, or which wireless setting meets a requirement. Match the setting to the goal: hide the network (disable beacons), keep the signal inside (power and direction), make traffic unreadable (WPA3/AES), keep strangers off (authentication, MAC filtering).

Connected topics

Videos

  • Wireless Security Settings - CompTIA Security+ SY0-701 - 4.1

    Professor MesserWatch on YouTube (opens in a new tab)

  • WiFi (Wireless) Password Security - WEP, WPA, WPA2, WPA3, WPS Explained

    PowerCert Animated VideosWatch on YouTube (opens in a new tab)

  • Port Security - CompTIA Security+ SY0-701 - 3.2

    Professor MesserWatch on YouTube (opens in a new tab)

  • Next-Gen Wi-Fi Security - WPA3 Explained

    TechquickieWatch on YouTube (opens in a new tab)

  • What is split tunneling? Here are the pros and cons

    TECHtalkWatch on YouTube (opens in a new tab)

Check yourself: 3.2 Protecting Networks: Managerial Controls and Wireless Security

4 questions on 3.2 Protecting Networks: Managerial Controls and Wireless Security. Pick an answer to see if you got it, and why.

Excerpt from the network security policy of Summit Health Partners, an invented organization:

Rule 1: Routers and switches may not have local user accounts. All administrator logins must go through the approved authentication server.

Rule 2: Unnecessary services, such as Telnet, must be disabled on all routers.

Rule 3: Port security must be enabled on every switch.

Rule 4: Only employees in approved roles may use the VPN, and they must use multifactor authentication.

Rule 5: Split tunneling is prohibited on all VPN connections.

Rule 6: All wireless traffic must be encrypted with AES using a minimum key length set by the security team.

Invented policy excerpt

Question 1 of 4

What kind of security control is this policy?

Question 2 of 4

Which rule most directly protects against an adversary who plugs a laptop into an open data port and floods a switch with MAC addresses?

Question 3 of 4

Why might Summit Health Partners prohibit split tunneling (Rule 5)?

Question 4 of 4

What is the main security benefit of Rule 1?

0 of 4 answered