CompTIA Network+ (N10-009)Network SecurityMedium

A network administrator is upgrading enterprise wireless security to eliminate the risk of offline dictionary attacks against captured pre-shared key handshakes, a well-known weakness of WPA2-PSK. Which technology should be implemented?

  1. AWEP with 128-bit keys
  2. BOpen authentication with a captive portal
  3. CWPA3 with Simultaneous Authentication of Equals (SAE)
  4. DWPA2 with TKIP
Show answer & explanation

Correct answer: C. WPA3 with Simultaneous Authentication of Equals (SAE)

WPA3 replaces the WPA2 four-way handshake with SAE, a Diffie-Hellman-based exchange that resists offline dictionary and brute-force attacks even if traffic is captured. WEP and TKIP are outdated and weaker, and an open network with a captive portal provides no encryption at the link layer.

Why the other options are wrong

  • A. WEP is severely broken and easily cracked, far weaker than WPA2.
  • B. Open/captive portal networks transmit unencrypted, exposing all traffic.
  • D. TKIP is a deprecated WPA2 cipher with known vulnerabilities, not a fix for offline attacks.

WPA3 SAE

WPA3's Simultaneous Authentication of Equals replaces WPA2's PSK handshake, using a secure key exchange that resists offline dictionary attacks even if the exchange is captured.

  • Also called the 'Dragonfly' handshake
  • Provides forward secrecy unlike WPA2-PSK
  • Resistant to offline brute-force even with captured traffic

Memory trick: SAE says: even if you catch it, you can't crack it.

More Network Security questions