ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityMedium
A company is implementing a new wireless network (WLAN) for its corporate offices. The security team requires the strongest available encryption and authentication for all wireless client connections, including mutual authentication between the client and the access point, and dynamic per-user encryption keys. Which of the following WLAN security standards should be chosen?
- AWi-Fi Protected Access 3 (WPA3)
- BWi-Fi Protected Access 2 (WPA2)
- CWired Equivalent Privacy (WEP)
- DWi-Fi Protected Access (WPA)
Show answer & explanationAnswer & explanation
Correct answer: A. Wi-Fi Protected Access 3 (WPA3)
WPA3 is the latest and most secure standard for WLANs, offering stronger encryption with Simultaneous Authentication of Equals (SAE) for robust mutual authentication and dynamic per-user keys, addressing vulnerabilities found in earlier standards.
Why the other options are wrong
- B. WPA2 uses AES encryption and 802.1X for authentication, but WPA3 offers further enhancements and addresses some WPA2 vulnerabilities (e.g., KRACK).
- C. WEP is highly insecure and easily cracked; it does not meet the requirements for strong encryption or mutual authentication.
- D. WPA (original) improved upon WEP but used TKIP, which has known vulnerabilities and is not considered strong encryption today.
WPA3
The latest Wi-Fi security standard providing enhanced cryptographic strength, improved authentication, and better protection against common attacks.
- Uses Simultaneous Authentication of Equals (SAE) for robust password-based authentication.
- Mandates Protected Management Frames (PMF) for management traffic integrity.
- Offers 192-bit encryption in Enterprise mode (CNSA suite).
Memory trick: Wireless security 'WE P'rotect 'A'll '2' '3' ways.