A network technician is configuring a secure wireless network for a regional field office. Management mandates enhancing security beyond WPA2-Personal to protect against offline dictionary attacks and wireless management frame spoofing, but the site lacks the infrastructure required for centralized RADIUS authentication. Which TWO of the following features or protocols must be implemented to fulfill these requirements under WPA3-Personal?
- Simultaneous Authentication of Equals (SAE) to replace the legacy pre-shared key handshake and defend against offline dictionary attacksAnswer
- Mandatory integration of Protected Management Frames (PMF / IEEE 802.11w) to safeguard unicast and multicast management traffic against spoofingAnswer
- CDeployment of an IEEE 802.1X framework with EAP-TLS authentication requiring central RADIUS servers and individual client certificates
- DCentralized credential validation via RADIUS to encrypt the entire 802.11 wireless frame payload and decouple authentication from authorization
Answer
Simultaneous Authentication of Equals (SAE) and mandatory Protected Management Frames (PMF / IEEE 802.11w) must be implemented for WPA3-Personal.
WPA3-Personal enhances wireless security by introducing Simultaneous Authentication of Equals (SAE) to eliminate vulnerability to offline dictionary attacks without requiring a RADIUS infrastructure. Additionally, WPA3 makes Protected Management Frames (PMF / IEEE 802.11w) mandatory to protect wireless management traffic from deauthentication spoofing.
Step-by-Step Solution
Key Concept
WPA3-Personal Security Enhancements (SAE and PMF)