CompTIA A+ Core 2 (220-1202)SecurityMedium
A company is upgrading its wireless network infrastructure. The security team requires a wireless security protocol that provides strong encryption and uses a unique encryption key for each wireless client session, eliminating the use of a shared pre-shared key. Which protocol best meets these requirements?
- AWPA3
- BWPA
- CWEP
- DWPA2
Show answer & explanationAnswer & explanation
Correct answer: A. WPA3
WPA3 introduces Simultaneous Authentication of Equals (SAE), which replaces the Pre-Shared Key (PSK) exchange with a more secure handshake. SAE provides forward secrecy and protects against offline dictionary attacks, ensuring a unique and robust encryption key for each client session, even in personal mode.
Why the other options are wrong
- B. WPA (TKIP) was an improvement over WEP but still had vulnerabilities and did not provide unique keys per session in personal mode.
- C. WEP is outdated and insecure, using weak encryption and static keys.
- D. WPA2 (CCMP/AES) is a strong protocol but in personal mode (WPA2-PSK) it relies on a shared pre-shared key, which is vulnerable to offline dictionary attacks if intercepted.
WPA3 with SAE
The latest Wi-Fi Protected Access security protocol, WPA3, which introduces Simultaneous Authentication of Equals (SAE) to replace the WPA2 Pre-Shared Key (PSK) exchange. SAE provides stronger key establishment and forward secrecy.
- Replaces WPA2-PSK with SAE
- Provides individual data encryption for each client
- Protects against offline dictionary attacks
- Offers forward secrecy
Memory trick: WEP was weak, WPA improved, WPA2 became standard, but WPA3 is the newest and most secure.