EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingHard
A network administrator is designing a secure wireless network for a new office. The requirements include strong encryption, mutual authentication using certificates, and protection against common wireless vulnerabilities like key reinstallation attacks. Which combination of security protocols and authentication methods would best meet these criteria?
- AWPA2-Enterprise with PEAP
- BWPA3-Personal with SAE
- CWPA3-Enterprise with EAP-TLS
- DWPA2-PSK with AES
Show answer & explanationAnswer & explanation
Correct answer: C. WPA3-Enterprise with EAP-TLS
WPA3-Enterprise offers the highest level of security, including protection against KRACK-like attacks through improved key management. EAP-TLS provides strong mutual authentication using digital certificates, which is more robust than password-based methods like PEAP or PSK.
Why the other options are wrong
- A. WPA2-Enterprise with PEAP uses password-based authentication, which is less secure than certificate-based EAP-TLS and is still susceptible to some WPA2 vulnerabilities.
- B. WPA3-Personal with SAE is designed for home/small office use, providing better security than WPA2-Personal, but lacks the enterprise-grade mutual certificate authentication required.
- D. WPA2-PSK with AES is vulnerable to dictionary attacks and does not offer mutual authentication with certificates.
WPA3-Enterprise with EAP-TLS
The most secure current wireless standard combining WPA3's enhanced cryptographic protections and key management with EAP-TLS for robust mutual authentication using digital certificates, offering superior defense against various wireless attacks.
- WPA3 provides Forward Secrecy and improved key management.
- EAP-TLS uses client and server certificates for mutual authentication.
- Offers the strongest protection against passive eavesdropping and impersonation.
Memory trick: WPA3 Enterprise and EAP-TLS provide the ultimate security shield.