A network technician is provisioning an isolated Wi-Fi network for temporary contractors at a branch office. The organization requires protection against offline dictionary attacks and passive eavesdropping, but explicitly wants to avoid the operational complexity of deploying an 802.1X RADIUS server or digital certificates. Which wireless security standard and authentication mechanism best meets these specifications?
- WPA3-Personal utilizing Simultaneous Authentication of Equals (SAE)Answer
- BWPA3-Enterprise utilizing 802.1X RADIUS authentication
- CWPA2-Personal utilizing a Pre-Shared Key (PSK) with AES-CCMP
- DWPA2-Enterprise utilizing TACACS+ for centralized key exchange
Answer
WPA3-Personal utilizing Simultaneous Authentication of Equals (SAE)
WPA3-Personal implements Simultaneous Authentication of Equals (SAE) in place of the static pre-shared key four-way handshake used in WPA2. SAE leverages a Dragonfly key exchange that mitigates offline dictionary attacks even when simple passphrases are used and delivers forward secrecy for session traffic without requiring 802.1X RADIUS servers.
Step-by-Step Solution
Key Concept
WPA3-Personal SAE vs. WPA3-Enterprise RADIUS authentication mechanisms
Estimated Time:1m 15s