CompTIA Network+ (N10-009)Network ImplementationHard

A security-conscious organization is upgrading its wireless network and wants to eliminate vulnerability to offline dictionary attacks against the pre-shared key exchange used in previous wireless security standards. Which feature of WPA3 directly addresses this concern?

  1. ASimultaneous Authentication of Equals (SAE)
  2. BAES-256 encryption for all data frames
  3. CMandatory use of open authentication
  4. DIncreased SSID broadcast interval
Show answer & explanation

Correct answer: A. Simultaneous Authentication of Equals (SAE)

WPA3 replaces WPA2's 4-way handshake (vulnerable to offline dictionary/KRACK attacks) with Simultaneous Authentication of Equals (SAE), a Diffie-Hellman-based key exchange that provides forward secrecy and resists offline password-guessing attacks. AES-256 is an encryption cipher but doesn't fix the handshake vulnerability, and the other options are unrelated security mechanisms.

Why the other options are wrong

  • B. AES encryption strength doesn't address handshake-based offline attacks.
  • C. Open authentication provides no encryption at all, making it far less secure.
  • D. SSID broadcast interval has no bearing on cryptographic security.

WPA3 SAE

Simultaneous Authentication of Equals is a secure key exchange protocol used in WPA3 that replaces WPA2's 4-way handshake, protecting against offline dictionary attacks and providing forward secrecy.

  • Based on Dragonfly (Diffie-Hellman derived) key exchange
  • Provides forward secrecy—past sessions stay secure if password is later compromised
  • Resistant to offline brute-force/dictionary attacks unlike WPA2-PSK

Memory trick: SAE: 'Secure And Equal' handshake beats offline guessing.

More Network Implementation questions