Captive portal
A web page that holds a newly connected device's traffic until the user authenticates, accepts terms or pays; common on guest Wi-Fi, it controls access but does not encrypt the connection.
A captive portal keeps a newly connected device in a restricted state and redirects its web traffic to a login or terms page. The device is released to the wider network only after the user authenticates, accepts an acceptable use policy, enters a voucher or pays. Captive portals are common on hotel, airport and corporate guest Wi-Fi, and RFC 8952 describes an architecture for them. For guests, a portal can act as a lightweight form of network access control.
A captive portal authorises access; it does not protect the traffic. Many portals sit on open networks, where traffic over the air is unencrypted unless the network uses Opportunistic Wireless Encryption or WPA2 or WPA3, so users still need TLS or a VPN. Access is commonly tied to the device’s MAC address after login, so another device that copies an authenticated address may use the session. Attackers also imitate portals on an evil twin access point to collect credentials. IEEE 802.1X, by contrast, authenticates the user or device before granting access, and on Wi-Fi the exchange yields keys that encrypt the session.
Exam relevance: a scenario is likely to offer a captive portal as the security answer for a guest network. Candidates are expected to see that it provides authentication, acceptance of terms and accountability, not confidentiality.