Soru

Zorluk: OrtaWireless Security Protocols (WPA, WPA2, WPA3)

A small business seeks to secure its employee Wi-Fi network against offline brute-force and dictionary attacks if wireless traffic captures occur. The company does not deploy a centralized AAA or RADIUS server. Which wireless security protocol and key exchange mechanism should be configured on the Wireless LAN Controller (WLC) to satisfy these requirements?

  1. WPA3-Personal using Simultaneous Authentication of Equals (SAE)Cevap
  2. B
    WPA2-Personal using Counter Mode Cipher Block Chaining Message Authentication Code Protocol (CCMP)
  3. C
    WPA3-Enterprise using 192-bit security suite mode with EAP-TLS
  4. D
    WPA2-Enterprise using Temporal Key Integrity Protocol (TKIP) with 802.1X

Cevap

WPA3-Personal using Simultaneous Authentication of Equals (SAE)
WPA3-Personal replaces the traditional WPA2 4-way handshake with Simultaneous Authentication of Equals (SAE), based on the Dragonfly key exchange algorithm. SAE provides forward secrecy and effectively mitigates offline dictionary and brute-force attacks even if passwords are simple, all without requiring an 802.1X RADIUS authentication server.

Adım Adım Çözüm

1
Analyze authentication infrastructure constraints
Since the organization has no AAA/RADIUS server, Enterprise modes (802.1X/EAP) cannot be implemented. The solution must use a Personal (Preshared Key) deployment model.
Enterprise security modes rely on 802.1X RADIUS communication to authenticate users against a centralized backend directory.
2
Evaluate key exchange mechanisms for PSK protection
WPA2-Personal uses a 4-way handshake vulnerable to offline dictionary/brute-force attacks if captured. WPA3-Personal replaces this mechanism with Simultaneous Authentication of Equals (SAE).
SAE is based on the Dragonfly handshake algorithm, which provides zero-knowledge proof key establishment, preventing passive offline key-cracking attempts.
3
Select the matching configuration option
WPA3-Personal utilizing SAE delivers pre-shared key simplicity without requiring RADIUS while guaranteeing protection against offline dictionary attacks.
Meets both operational constraints: no RADIUS server required and resistant to handshake capture attacks.

Anahtar Kavram

Wireless Security Protocols: WPA3-Personal SAE vs WPA2-Personal PSK
Bu soruyu puanla