Soru

Zorluk: Çok zorWireless Security Protocols (WPA, WPA2, WPA3)

A network administrator configures a dual-mode WLAN on a Cisco Wireless LAN Controller (WLC) intended to support both modern WPA3-Personal devices and legacy WPA2-Personal client hardware during a corporate migration. WPA3-capable endpoints connect seamlessly; however, older WPA2-only devices consistently fail during the 802.11 association phase and cannot establish network connectivity. Frame captures reveal that the legacy stations receive association responses containing mandatory Protected Management Frames (PMF/802.11w) requirements. Which WLC configuration modification resolves this association failure for legacy endpoints while continuing to support WPA3-Personal clients?

  1. Set Management Frame Protection (MFP/PMF) to Optional (Capable) on the WLAN profile, allowing legacy stations without 802.11w support to associate.Cevap
  2. B
    Enforce Simultaneous Authentication of Equals (SAE) as the exclusive key management method so WPA2 stations can utilize legacy 4-way handshakes.
  3. C
    Change the default unicast encryption cipher suite from AES-CCMP128 to GCMP256 across all WLAN security policy profiles.
  4. D
    Disable 802.1X authentication parameters on the RADIUS server profile to allow local EAP fallback for legacy pre-shared key processing.

Cevap

Setting Management Frame Protection (MFP/PMF) to Optional (Capable) on the WLAN profile allows legacy stations without 802.11w support to associate.
The choice stating to set Management Frame Protection (MFP/PMF) to Optional (Capable) is correct because IEEE 802.11w PMF is mandatory in WPA3. When configuring WPA3-Personal Transition Mode to accommodate legacy WPA2 devices, setting PMF to Required prevents legacy clients that lack PMF code or hardware support from completing the 802.11 association process. Changing PMF to Optional enables WPA3 endpoints to use PMF while permitting WPA2 endpoints to connect without it.

Adım Adım Çözüm

1
Analyze the WPA3-Personal vs WPA2-Personal migration requirements.
WPA3 mandates Protected Management Frames (PMF / IEEE 802.11w) and Simultaneous Authentication of Equals (SAE).
WPA3 security standards enforce PMF to prevent management frame spoofing attacks such as deauthentication attacks.
2
Evaluate the cause of the association failure for legacy WPA2 devices in transition mode.
Setting PMF to Required on the WLC forces all associating clients to support IEEE 802.11w. Legacy devices lacking 802.11w capabilities reject or are rejected during the association frame exchange.
Transition mode requires backward-compatible settings for optional feature negotiation.
3
Determine the correct WLC configuration adjustment.
Configuring PMF as Optional (Capable) on the WLAN allows WPA3 clients to negotiate PMF while permitting legacy WPA2 clients lacking 802.11w to complete association.
This configuration balances the strict security requirements of WPA3 with the physical hardware limitations of legacy WPA2 endpoints.

Anahtar Kavram

WPA3 Transition Mode and Protected Management Frames (PMF / IEEE 802.11w) compatibility requirements
Bu soruyu puanla