A network security administrator is configuring wireless security policies for remote retail branches that lack 802.1X/RADIUS authentication infrastructure. The new security baseline requires protecting modern client connections against offline dictionary attacks and wireless deauthentication frame spoofing. However, legacy Wi-Fi 5 point-of-sale terminals that only support WPA2-Personal (AES-CCMP) and do not support 802.11w Protected Management Frames (PMF) must continue operating on the same SSID until phase-out. Which of the following security settings must the administrator configure on the wireless controllers to meet all operational and security criteria? (Select TWO)
- Enable WPA3-Personal Transition Mode to allow Simultaneous Authentication of Equals (SAE) for supporting devices alongside WPA2-Personal (CCMP) fallback.Answer
- Configure Protected Management Frames (PMF / 802.11w) as optional or capable rather than required.Answer
- CDeploy WPA3-Enterprise 192-bit mode with EAP-TLS authentication across all branch access points.
- DEnable Temporal Key Integrity Protocol (TKIP) key mixing on the WPA3 pre-shared key profile for legacy backward compatibility.
Answer
The administrator must enable WPA3-Personal Transition Mode with Simultaneous Authentication of Equals (SAE) and set Protected Management Frames (PMF / 802.11w) to optional (capable).
WPA3-Personal Transition Mode permits both WPA3-Personal (using SAE to resist dictionary attacks) and WPA2-Personal (using AES-CCMP) to operate on the same SSID. Additionally, setting PMF (802.11w) to optional/capable permits legacy terminals that lack 802.11w support to connect while still enforcing management frame encryption/integrity for modern supporting clients.
Step-by-Step Solution
Key Concept
WPA3-Personal Transition Mode & PMF Negotiation
Estimated Time:2m 0s