A network engineer is configuring a single Service Set Identifier (SSID) on an enterprise wireless access point to support both modern corporate laptops and legacy handheld scanners during a phased migration to WPA3. To achieve backward compatibility without establishing separate wireless networks, the engineer selects WPA3-Personal Transition Mode. Which TWO of the following technical requirements and configurations must be implemented on the access point for this deployment? (Select TWO.)
- Simultaneous Authentication of Equals (SAE) must operate alongside WPA2 Pre-Shared Key (PSK) authentication.Answer
- Protected Management Frames (PMF) must be configured as optional/capable rather than mandatory.Answer
- C802.1X RADIUS authentication must be enabled to issue individualized session keys for legacy devices.
- DTemporal Key Integrity Protocol (TKIP) must be enabled as the fallback cipher suite for WPA2 connections.
Answer
Simultaneous Authentication of Equals (SAE) operating alongside WPA2 Pre-Shared Key (PSK) authentication, and Protected Management Frames (PMF) configured as optional/capable rather than mandatory.
WPA3-Personal Transition Mode is designed for dual-stack legacy compatibility. It enables Simultaneous Authentication of Equals (SAE) for modern clients while allowing legacy clients to authenticate using Pre-Shared Key (PSK) with AES-CCMP encryption. Furthermore, because Protected Management Frames (PMF/802.1w) are mandatory in pure WPA3 but unsupported by legacy WPA2 devices, the access point must set PMF to optional/capable to permit legacy association.
Step-by-Step Solution
Key Concept
WPA3-Personal Transition Mode Requirements and PMF Negotiation
Estimated Time:2m 0s