Cisco CCNA (200-301)Security FundamentalsEasy

A small business owner wants to upgrade wireless security from WPA2-Personal to WPA3-Personal because employees complain that a shared passphrase is vulnerable to offline dictionary attacks. Which feature of WPA3 directly addresses this concern?

  1. AAES-256 encryption applied to all wireless frames
  2. BSimultaneous Authentication of Equals (SAE) key exchange
  3. CMandatory 802.1X authentication for all clients
  4. DA longer 128-bit pre-shared key requirement
Show answer & explanation

Correct answer: B. Simultaneous Authentication of Equals (SAE) key exchange

WPA3-Personal replaces the WPA2 4-way handshake with SAE (Simultaneous Authentication of Equals), a Dragonfly-based key exchange that resists offline dictionary and brute-force attacks even when a weak passphrase is used.

Why the other options are wrong

  • A. AES encryption strength doesn't stop offline dictionary attacks on the handshake.
  • C. 802.1X is used in Enterprise mode, not Personal mode.
  • D. WPA3-Personal does not mandate a longer key length.

WPA3 SAE

SAE is the key establishment protocol in WPA3-Personal that replaces the WPA2 4-way handshake and protects against offline dictionary attacks.

  • SAE = Simultaneous Authentication of Equals
  • Also called Dragonfly handshake
  • Resists offline brute-force even with weak passphrases

Memory trick: SAE 'Says Absolutely no Eavesdropping' on offline guesses.

More Security Fundamentals questions