Soru

Zorluk: OrtaWireless Security Protocols (WPA, WPA2, WPA3)

A network engineer is reviewing security standards to upgrade an organization's wireless network infrastructure to WPA3. Which TWO statements accurately describe the security enhancements and requirements introduced in WPA3 compared to WPA2? (Select two.)

  1. WPA3-Personal replaces the legacy pre-shared key (PSK) four-way handshake with Simultaneous Authentication of Equals (SAE) to protect against offline dictionary attacks.Cevap
  2. WPA3 mandates the use of Protected Management Frames (PMF) across all connections to defend against wireless management frame spoofing.Cevap
  3. C
    WPA3-Personal requires a centralized RADIUS server for IEEE 802.1X user authentication during client association.
  4. D
    WPA3 relies on Temporal Key Integrity Protocol (TKIP) to deliver 256-bit encryption for high-density client deployments.

Cevap

WPA3 introduces Simultaneous Authentication of Equals (SAE) in Personal mode to protect against dictionary attacks, and mandates Protected Management Frames (PMF) on all connections.
WPA3 introduces key cryptographic enhancements over WPA2. First, WPA3-Personal replaces the legacy WPA2 PSK four-way handshake with Simultaneous Authentication of Equals (SAE), which protects against offline dictionary attacks and provides forward secrecy. Second, WPA3 mandates Protected Management Frames (PMF / IEEE 802.11w) across all client connections to protect against management frame injection and deauthentication attacks.

Adım Adım Çözüm

1
Analyze WPA3-Personal authentication improvements over WPA2-Personal.
Identified that WPA3-Personal replaces the PSK four-way handshake with Simultaneous Authentication of Equals (SAE), preventing offline password guessing.
SAE uses Dragonfly key exchange so that an attacker capturing the handshake cannot perform offline dictionary attacks.
2
Evaluate management frame protection requirements in WPA3.
Confirmed that Protected Management Frames (PMF / IEEE 802.11w) are mandatory in WPA3.
PMF prevents deauthentication and disassociation spoofing attacks by encrypting/authenticating management frames.
3
Examine distractor statements regarding RADIUS deployment and TKIP ciphers.
Disqualified statements claiming WPA3-Personal requires RADIUS or that WPA3 uses TKIP.
RADIUS is required for 802.1X Enterprise mode, not Personal mode. TKIP is an insecure legacy cipher prohibited in WPA3.

Anahtar Kavram

WPA3 Security Improvements: SAE Key Exchange and Mandatory PMF
Tahmini Süre:1m 30s
Bu soruyu puanla