CompTIA Network+ (N10-009)Network ImplementationHard
A security-conscious organization is upgrading its wireless network and wants to eliminate vulnerability to offline dictionary attacks against the pre-shared key exchange used in previous wireless security standards. Which feature of WPA3 directly addresses this concern?
- ASimultaneous Authentication of Equals (SAE)
- BAES-256 encryption for all data frames
- CMandatory use of open authentication
- DIncreased SSID broadcast interval
Show answer & explanationAnswer & explanation
Correct answer: A. Simultaneous Authentication of Equals (SAE)
WPA3 replaces WPA2's 4-way handshake (vulnerable to offline dictionary/KRACK attacks) with Simultaneous Authentication of Equals (SAE), a Diffie-Hellman-based key exchange that provides forward secrecy and resists offline password-guessing attacks. AES-256 is an encryption cipher but doesn't fix the handshake vulnerability, and the other options are unrelated security mechanisms.
Why the other options are wrong
- B. AES encryption strength doesn't address handshake-based offline attacks.
- C. Open authentication provides no encryption at all, making it far less secure.
- D. SSID broadcast interval has no bearing on cryptographic security.
WPA3 SAE
Simultaneous Authentication of Equals is a secure key exchange protocol used in WPA3 that replaces WPA2's 4-way handshake, protecting against offline dictionary attacks and providing forward secrecy.
- Based on Dragonfly (Diffie-Hellman derived) key exchange
- Provides forward secrecy—past sessions stay secure if password is later compromised
- Resistant to offline brute-force/dictionary attacks unlike WPA2-PSK
Memory trick: SAE: 'Secure And Equal' handshake beats offline guessing.