Cisco CCNA (200-301)Security FundamentalsEasy
A small business owner wants to upgrade wireless security from WPA2-Personal to WPA3-Personal because employees complain that a shared passphrase is vulnerable to offline dictionary attacks. Which feature of WPA3 directly addresses this concern?
- AAES-256 encryption applied to all wireless frames
- BSimultaneous Authentication of Equals (SAE) key exchange
- CMandatory 802.1X authentication for all clients
- DA longer 128-bit pre-shared key requirement
Show answer & explanationAnswer & explanation
Correct answer: B. Simultaneous Authentication of Equals (SAE) key exchange
WPA3-Personal replaces the WPA2 4-way handshake with SAE (Simultaneous Authentication of Equals), a Dragonfly-based key exchange that resists offline dictionary and brute-force attacks even when a weak passphrase is used.
Why the other options are wrong
- A. AES encryption strength doesn't stop offline dictionary attacks on the handshake.
- C. 802.1X is used in Enterprise mode, not Personal mode.
- D. WPA3-Personal does not mandate a longer key length.
WPA3 SAE
SAE is the key establishment protocol in WPA3-Personal that replaces the WPA2 4-way handshake and protects against offline dictionary attacks.
- SAE = Simultaneous Authentication of Equals
- Also called Dragonfly handshake
- Resists offline brute-force even with weak passphrases
Memory trick: SAE 'Says Absolutely no Eavesdropping' on offline guesses.