Cisco CCNA (200-301)Security FundamentalsEasy
A wireless network engineer is planning security for a new SOHO access point. The client wants a solution that resists offline dictionary attacks even if the pre-shared key is weak, without requiring a RADIUS server. Which technology should be enabled?
- AWPA2-Enterprise
- BWPA2-Personal
- CWEP with a 128-bit key
- DWPA3-Personal (SAE)
Show answer & explanationAnswer & explanation
Correct answer: D. WPA3-Personal (SAE)
WPA3-Personal uses Simultaneous Authentication of Equals (SAE), which replaces the WPA2 4-way handshake and protects against offline dictionary/brute-force attacks even with weaker passwords, without needing a RADIUS server.
Why the other options are wrong
- A. Enterprise mode requires a RADIUS server, which the client wants to avoid.
- B. WPA2-Personal's 4-way handshake is vulnerable to offline dictionary attacks (e.g., KRACK).
- C. WEP is obsolete and trivially broken.
WPA3-SAE
WPA3-Personal replaces the WPA2 PSK 4-way handshake with Simultaneous Authentication of Equals (SAE), a secure key-agreement protocol.
- SAE resists offline dictionary attacks
- No RADIUS server needed for Personal mode
- WPA2 4-way handshake is vulnerable to KRACK attacks
Memory trick: SAE Says Attackers Excluded