Wireless access point

The device that connects wireless clients to a wired network: it advertises the network, handles association and enforces the Wi-Fi security mode configured on it.

A wireless access point (WAP, or simply AP) is the device that joins wireless clients to a wired network. It advertises the network’s SSID, accepts client associations and bridges frames between the radio side and the wired side. It also enforces the link security configured on it. In WPA2 or WPA3 Personal mode, it checks the shared passphrase itself. In Enterprise mode, it acts as the authenticator in IEEE 802.1X, relaying the exchange to an authentication server, commonly a RADIUS server, and enforcing the result.

An access point is a doorway onto the internal network. A rogue access point is one connected to the network without authorisation, often by an employee for convenience, and it can bypass the controls the official ones enforce. An evil twin imitates a legitimate network’s SSID to draw clients to the attacker. Default credentials and outdated firmware weaken the device itself. Placement and transmit power decide how far the signal carries beyond the building, which affects exposure to war driving.

Exam relevance: questions in this area tend to turn on telling an unauthorised device from an impostor. Candidates are expected to keep a rogue access point (an unapproved device on your network) apart from an evil twin (an attacker’s device posing as your network), and to know the access point’s role in 802.1X.