A network engineer is reviewing security standards to upgrade an organization's wireless network infrastructure to WPA3. Which TWO statements accurately describe the security enhancements and requirements introduced in WPA3 compared to WPA2? (Select two.)
- WPA3-Personal replaces the legacy pre-shared key (PSK) four-way handshake with Simultaneous Authentication of Equals (SAE) to protect against offline dictionary attacks.Answer
- WPA3 mandates the use of Protected Management Frames (PMF) across all connections to defend against wireless management frame spoofing.Answer
- CWPA3-Personal requires a centralized RADIUS server for IEEE 802.1X user authentication during client association.
- DWPA3 relies on Temporal Key Integrity Protocol (TKIP) to deliver 256-bit encryption for high-density client deployments.
Answer
WPA3 introduces Simultaneous Authentication of Equals (SAE) in Personal mode to protect against dictionary attacks, and mandates Protected Management Frames (PMF) on all connections.
WPA3 introduces key cryptographic enhancements over WPA2. First, WPA3-Personal replaces the legacy WPA2 PSK four-way handshake with Simultaneous Authentication of Equals (SAE), which protects against offline dictionary attacks and provides forward secrecy. Second, WPA3 mandates Protected Management Frames (PMF / IEEE 802.11w) across all client connections to protect against management frame injection and deauthentication attacks.
Step-by-Step Solution
Key Concept
WPA3 Security Improvements: SAE Key Exchange and Mandatory PMF
Estimated Time:1m 30s