ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityHard
A security architect is designing a secure wireless network for a government agency handling classified information. The primary concern is protecting against passive eavesdropping and ensuring strong mutual authentication between wireless clients and access points (APs). The solution must use the strongest available encryption and authentication protocols for enterprise environments. Which wireless security standard and protocol combination should be recommended?
- AWPA2-Enterprise with AES and EAP-TLS
- BWPA3-Personal with SAE and CCMP
- CWPA2-PSK with TKIP
- DWEP with RC4
Show answer & explanationAnswer & explanation
Correct answer: A. WPA2-Enterprise with AES and EAP-TLS
For government agencies handling classified information, WPA2-Enterprise with AES (CCMP) and EAP-TLS provides robust security. WPA3 is newer but EAP-TLS provides the strongest mutual authentication, often required for high-security environments, and WPA2-Enterprise with AES (CCMP) is still considered strong and widely supported.
Why the other options are wrong
- B. WPA3-Personal with SAE is for personal use and does not provide the centralized authentication and mutual certificate-based authentication required for a government enterprise.
- C. WPA2-PSK with TKIP is for personal use and TKIP is deprecated, offering weaker security than AES.
- D. WEP with RC4 is obsolete and highly vulnerable, offering no meaningful security for classified information.
WPA2-Enterprise (EAP-TLS)
An enterprise-grade wireless security standard utilizing 802.1X for centralized authentication and EAP-TLS for strong mutual authentication with digital certificates, coupled with AES encryption.
- Uses 802.1X for centralized authentication (RADIUS).
- EAP-TLS provides strongest mutual authentication (certificates).
- Encrypts traffic with AES (CCMP).
Memory trick: WEP is weak, WPA2-Enterprise is strong.