SSCP Systems Security Certified PractitionerNetwork and Communications SecurityHard
A network security engineer is configuring a wireless network for a critical industrial control system (ICS). Due to the sensitive nature of the data and the need for strict authentication, the engineer wants to use the strongest available encryption and authentication protocols. Which combination of protocols should be selected?
- AWPA2-Enterprise with TKIP
- BWPA2-PSK with AES
- CWPA3-Enterprise with EAP-TLS
- DWPA3-Enterprise with OWE
Show answer & explanationAnswer & explanation
Correct answer: C. WPA3-Enterprise with EAP-TLS
WPA3-Enterprise offers the strongest current encryption and security features. When combined with EAP-TLS, which uses digital certificates for mutual authentication, it provides the most robust authentication and encryption for highly sensitive environments like ICS.
Why the other options are wrong
- A. WPA2-Enterprise is less secure than WPA3, and TKIP is an outdated and insecure encryption protocol, making this a poor choice.
- B. WPA2-PSK (Pre-Shared Key) is suitable for home/small office but lacks individual user authentication and is less secure than Enterprise modes.
- D. WPA3-Enterprise is correct, but OWE (Opportunistic Wireless Encryption) is for open networks to provide unauthenticated encryption, not for strong authentication in sensitive systems.
WPA3-Enterprise with EAP-TLS
The most secure wireless encryption and authentication standard, combining WPA3's advanced features with certificate-based EAP-TLS for mutual authentication.
- WPA3 offers enhanced security over WPA2.
- Enterprise mode uses 802.1X for authentication.
- EAP-TLS uses digital certificates for strong mutual authentication (client and server).
- Ideal for highly sensitive environments requiring maximum security.
Memory trick: Wireless Needs Enterprise-Level Trust.