CompTIA Network+ (N10-009)Network SecurityMedium
A network administrator is upgrading enterprise wireless security to eliminate the risk of offline dictionary attacks against captured pre-shared key handshakes, a well-known weakness of WPA2-PSK. Which technology should be implemented?
- AWEP with 128-bit keys
- BOpen authentication with a captive portal
- CWPA3 with Simultaneous Authentication of Equals (SAE)
- DWPA2 with TKIP
Show answer & explanationAnswer & explanation
Correct answer: C. WPA3 with Simultaneous Authentication of Equals (SAE)
WPA3 replaces the WPA2 four-way handshake with SAE, a Diffie-Hellman-based exchange that resists offline dictionary and brute-force attacks even if traffic is captured. WEP and TKIP are outdated and weaker, and an open network with a captive portal provides no encryption at the link layer.
Why the other options are wrong
- A. WEP is severely broken and easily cracked, far weaker than WPA2.
- B. Open/captive portal networks transmit unencrypted, exposing all traffic.
- D. TKIP is a deprecated WPA2 cipher with known vulnerabilities, not a fix for offline attacks.
WPA3 SAE
WPA3's Simultaneous Authentication of Equals replaces WPA2's PSK handshake, using a secure key exchange that resists offline dictionary attacks even if the exchange is captured.
- Also called the 'Dragonfly' handshake
- Provides forward secrecy unlike WPA2-PSK
- Resistant to offline brute-force even with captured traffic
Memory trick: SAE says: even if you catch it, you can't crack it.