Wireless and Mobile Security
CET2850 — Wireless and Mobile Security
← Course Modules
Course Description
Wireless and Mobile Security addresses the growing reliance on wireless and mobile devices in both workplace and home environments. Students examine security considerations for this expanding technology sector and explore strategies for protecting organisational and personal assets in the mobile device landscape.
Within the SCNS taxonomy, CET is the Computer Engineering Technology prefix. Daytona State publishes this at 3 credits, offered spring, with CET1600 as prerequisite and CTS2321 as corequisite, giving approximately 45 contact hours at the prefix's unsuffixed convention.
Wireless and mobile is where the traditional network perimeter stopped working. A wired network has a physical boundary; a wireless one radiates past the walls, and a mobile device leaves the building in someone's pocket and returns having connected to a dozen untrusted networks. That shift is why identity and device posture, rather than network location, now carry the weight in enterprise security design.
Daytona State does not publish a lecture and laboratory split for its CET courses. The prefix's unsuffixed courses run consistently at 15 contact hours per credit — CET1588, CET2544, CET2691, CET2792, CET2793, CET2794, CET3505 and CET4542 are all published at 3 credits and 45 hours, without exception. Its C-suffixed courses run at 20 or above and its L-suffixed laboratories at 30. This course is unsuffixed and is priced at the unsuffixed convention.
Learning Outcomes
Required Outcomes
- Describe wireless networking standards and their security characteristics.
- Describe radio frequency fundamentals relevant to wireless security.
- Describe wireless authentication and encryption mechanisms.
- Compare WEP, WPA, WPA2 and WPA3 and describe the weaknesses of each.
- Configure a wireless access point securely.
- Configure enterprise wireless authentication using 802.1X and RADIUS.
- Describe common wireless attacks and their mechanisms.
- Identify rogue access points and evil twin attacks.
- Describe deauthentication, jamming, and denial of service against wireless.
- Conduct authorised wireless site survey and assessment.
- Describe wireless intrusion detection and prevention.
- Segment wireless networks appropriately, including guest access.
- Describe mobile device operating systems and their security models.
- Describe application sandboxing and permission models.
- Describe mobile malware and its distribution routes.
- Describe mobile device management and enterprise mobility management.
- Configure device policies, encryption, and remote wipe.
- Describe bring-your-own-device policy and its risks and trade-offs.
- Describe containerisation and separation of work and personal data.
- Describe Bluetooth, NFC, and other short-range protocol risks.
- Describe internet-of-things device risk in home and enterprise settings.
- Apply defence in depth to a wireless and mobile environment.
- Develop a wireless and mobile security policy.
- Describe legal and privacy constraints on monitoring personal devices.
Optional Outcomes
- Perform authorised wireless penetration testing.
- Describe cellular network security.
- Perform mobile application security assessment.
- Describe mobile device forensics at an introductory level.
- Describe zero-trust architecture principles.
- Prepare for a wireless or mobile security certification.
Major Topics
Required Topics
- Wireless standards and security
- Radio frequency fundamentals
- Wireless authentication and encryption
- WEP, WPA, WPA2 and WPA3
- Securing an access point
- 802.1X and RADIUS
- Wireless attacks
- Rogue access points and evil twins
- Deauthentication and jamming
- Authorised site survey and assessment
- Wireless intrusion detection
- Network segmentation and guest access
- Mobile operating system security models
- Sandboxing and permissions
- Mobile malware
- Mobile device management
- Device policy, encryption, and remote wipe
- Bring-your-own-device policy
- Containerisation
- Bluetooth, NFC, and short-range risk
- Internet-of-things risk
- Defence in depth
- Wireless and mobile policy
- Legal and privacy constraints
Optional Topics
- Authorised wireless penetration testing
- Cellular network security
- Mobile application assessment
- Introductory mobile forensics
- Zero-trust architecture
- Certification preparation
Resources & Tools
- The programme's laboratory and its isolated network — the only place you can lawfully practise most of this. Use every scheduled hour and every open-lab hour.
- Virtualisation software — VirtualBox is free, VMware Workstation Player is free for personal use; a home lab of virtual machines costs nothing but disk space.
- Kali Linux and the SANS SIFT Workstation — free tool distributions for security testing and forensics respectively.
- Autopsy and The Sleuth Kit (sleuthkit.org) — free and open-source forensic tools used professionally, not merely for teaching.
- NIST Computer Forensics Tool Testing programme (cftt.nist.gov) — free tool validation reports; the reference when you need to defend a tool choice.
- NIST Special Publications, especially SP 800-86 (forensic techniques in incident response) and SP 800-61 (incident handling) — free, authoritative, and directly examinable.
- CISA (cisa.gov) — free advisories, guidance, and free training resources.
- MITRE ATT&CK (attack.mitre.org) — free; the standard framework for describing adversary behaviour, and increasingly expected knowledge.
- TryHackMe, Hack The Box, and OverTheWire — lawful practice environments, with free tiers; the right place to practise offensive technique.
- CompTIA and Cisco Networking Academy materials — aligned to the certifications employers ask for.
Career Pathways
- Information security analyst — SOC 15-1212; consistently among the fastest-growing occupations.
- Computer network support specialist — SOC 15-1231; computer user support specialist — SOC 15-1232.
- Network and computer systems administrator — SOC 15-1244.
- Digital forensics examiner — in law enforcement, in corporate investigations, and in consulting firms.
- Incident responder and security operations centre analyst — a large and growing entry route into security.
- Electrical and electronics engineering technologist or technician — SOC 17-3023, for the digital design pathway.
- Embedded systems and FPGA development — a specialised, well-paid pathway from the digital design sequence.
- Florida's defence, space, and simulation sector — the Space Coast, Orlando's simulation and training cluster, and Tampa's defence presence all hire heavily in these areas, and many roles require U.S. citizenship and a security clearance.
- Public sector and law enforcement — state and county agencies, and federal offices with a large Florida presence.
- Healthcare, financial services, and hospitality IT — all large Florida sectors with substantial compliance-driven security demand.
- Consulting and managed security service providers.
- ⚠ Many security and forensics roles require a clean background — criminal history, and for cleared work significant unresolved debt or foreign contacts, can be disqualifying. Find this out before investing in the pathway.
Special Information
⚠ Bring-your-own-device is a policy problem before it is a technical one
- The hard questions in mobile security are about ownership and expectation, not encryption. Whose device is it, whose data is on it, and what may the employer do to it?
- Remote wipe of a personal device destroys personal data — photographs, messages, everything — and an employee who was not told that in advance will be justifiably angry and may have a legal complaint.
- Containerisation separates work and personal data so that only the work container is managed and wiped. It is the answer to most of the tension, and it needs to be chosen deliberately.
- Monitoring a personal device raises privacy questions that vary by jurisdiction and by what the employee agreed to. Written, signed, plain-language policy is the control, and it must be presented before enrolment, not after.
- Lost and stolen devices are the common incident, not sophisticated attacks. Encryption, screen lock, and a working wipe capability handle most of the real risk.
- Departing employees are a specific problem. Off-boarding must remove access and company data from personal devices, and it is routinely forgotten.
- Users route around policies that make their work harder, so an unusable policy produces shadow IT rather than security.
- ⚠ Rule 11 applies — workplace privacy and monitoring law changes and varies; involve counsel and human resources in policy design.
⚠⚠ Authorisation is the line between a security professional and a defendant
- Never access, scan, or test a system you do not have written permission to touch. Not a friend's network, not your employer's without authority, not a "harmless" port scan of a site you use. This is the one rule in this field that carries criminal consequences.
- Federal exposure: the Computer Fraud and Abuse Act criminalises unauthorised access to a protected computer, and "exceeding authorised access" has been read broadly.
- ⚠⚠ Florida exposure is separate and additional: the Florida Computer Crimes Act, Chapter 815, Florida Statutes, makes offences against intellectual property, computer users, and computer equipment punishable under state law independently of federal law. A student who assumes only federal law applies is wrong.
- Curiosity is not a defence, and neither is intent to help. Discovering a vulnerability and testing it without authorisation is an offence even when you meant to report it.
- Use the lab. Your programme provides an isolated environment precisely so you can practise techniques that would be unlawful elsewhere — build your own isolated lab at home too, and keep it off the production network.
- Get scope in writing before any authorised engagement — systems, addresses, times, techniques permitted, and who to contact when something breaks. A verbal "go ahead" protects nobody.
- Stay inside scope once you start. Following an interesting path onto a system not covered by the authorisation is where legitimate testers get into trouble.
- Responsible disclosure has a process. Follow the vendor's or organisation's published route, and do not publish details before it has been addressed.
- ⚠ Rule 11 applies. Computer crime, privacy, and disclosure law changes; verify current law and take advice rather than relying on a course guide.
⚠ Certifications carry real weight in this field — more than in most
- Information technology and security hire on demonstrated capability, and certifications are the common shorthand for it — frequently appearing as hard requirements in job postings and in government and contractor roles.
- Foundational: CompTIA A+ (hardware and operating systems), Network+, and Security+. Security+ in particular satisfies a widely cited U.S. Department of Defense baseline requirement, which makes it valuable in Florida's substantial defence and contractor sector.
- Networking: Cisco CCNA remains the recognised entry credential.
- Digital forensics: EnCE (EnCase), ACE (AccessData), CCE, and the SANS GCFE and GCFA. The SANS credentials are the most respected and by far the most expensive — employers frequently pay for them, so raise it at interview rather than self-funding.
- Security management: CISSP is the senior standard but requires several years of documented experience; SSCP is its practitioner-level counterpart and is reachable earlier.
- Time your certification to your coursework. Sit the examination while the material is fresh — pass rates fall sharply the longer graduates wait.
- Certifications expire. Most require continuing education and renewal, so plan for the ongoing cost.
- ⚠ A certification is not a substitute for the degree, and the degree is not a substitute for certifications. Employers in this field commonly want both, plus evidence you have actually built and broken things.
- Build a home lab and document it. Virtual machines cost nothing, and a candidate who can describe what they built and what went wrong interviews far better than one who lists courses.
How Florida course levels affect transfer
The first digit of an SCNS number denotes the year of offering, not transferability. Courses at the 1000 and 2000 levels transfer transparently between Florida public institutions, and 3000 to 4000 is unproblematic since both are upper division. The boundary that actually matters is 2000 to 3000, where lower-division credit generally cannot satisfy an upper-division requirement.
⚠ That boundary is live in this prefix. Daytona State offers CET courses at the 1000, 2000, 3000 and 4000 levels, the upper-division ones forming part of a bachelor of applied science. A 2000-level CET course does not substitute for its 3000- or 4000-level counterpart even where the subject matter overlaps — compare CET2880C/CET2881C (Data Forensics I and II, lower division) with CET4860/CET4861 (Introduction to and Advanced Digital Forensics, upper division). Confirm with an advisor which lower-division courses feed the BAS.
CET2850 is 3 credits and approximately 45 contact hours, offered spring at Daytona State, with CET1600 as prerequisite and CTS2321 as corequisite.
See this repository's CET2883C, CET2890C, and CET2892C guides for the surrounding network security sequence.