Cisco CCNA (200-301)Security FundamentalsEasy

A wireless network engineer is planning security for a new SOHO access point. The client wants a solution that resists offline dictionary attacks even if the pre-shared key is weak, without requiring a RADIUS server. Which technology should be enabled?

  1. AWPA2-Enterprise
  2. BWPA2-Personal
  3. CWEP with a 128-bit key
  4. DWPA3-Personal (SAE)
Show answer & explanation

Correct answer: D. WPA3-Personal (SAE)

WPA3-Personal uses Simultaneous Authentication of Equals (SAE), which replaces the WPA2 4-way handshake and protects against offline dictionary/brute-force attacks even with weaker passwords, without needing a RADIUS server.

Why the other options are wrong

  • A. Enterprise mode requires a RADIUS server, which the client wants to avoid.
  • B. WPA2-Personal's 4-way handshake is vulnerable to offline dictionary attacks (e.g., KRACK).
  • C. WEP is obsolete and trivially broken.

WPA3-SAE

WPA3-Personal replaces the WPA2 PSK 4-way handshake with Simultaneous Authentication of Equals (SAE), a secure key-agreement protocol.

  • SAE resists offline dictionary attacks
  • No RADIUS server needed for Personal mode
  • WPA2 4-way handshake is vulnerable to KRACK attacks

Memory trick: SAE Says Attackers Excluded

More Security Fundamentals questions