A network security architect at a high-security research institution is deploying a new wireless network to comply with National Security Agency (NSA) Commercial National Security Algorithm (CNSA) Suite standards. The compliance mandate specifies that all wireless communications must use 192-bit cryptographic strength for both data confidentiality and integrity, paired with centralized identity management. Which configuration combination on the wireless LAN controller (WLC) and authentication server satisfies all aspects of this security mandate?
- WPA3-Enterprise 192-bit Mode using GCMP-256 encryption cipher and 802.1X RADIUS authentication with EAP-TLSCevap
- BWPA3-Personal using Simultaneous Authentication of Equals (SAE) with GCMP-256 encryption cipher
- CWPA3-Enterprise 192-bit Mode using AES-CCMP-128 encryption cipher and TACACS+ authentication with EAP-FAST
- DWPA2-Enterprise using AES-CCMP-256 encryption cipher and 802.1X RADIUS authentication with EAP-PEAPv0/MSCHAPv2
Cevap
WPA3-Enterprise 192-bit Mode using GCMP-256 encryption cipher and 802.1X RADIUS authentication with EAP-TLS is the correct configuration.
WPA3-Enterprise 192-bit Mode is specifically designed for high-security enterprise environments (such as government, financial, and military networks) adhering to the NSA's CNSA Suite. It requires 256-bit Galois/Counter Mode Protocol (GCMP-256) for data encryption, GMAC-256 for Protected Management Frames, 384-bit Elliptic Curve Diffie-Hellman (ECDHE) key exchange, and 802.1X RADIUS authentication using EAP-TLS with digital certificates.
Adım Adım Çözüm
Anahtar Kavram
WPA3-Enterprise 192-bit Security Mode and CNSA Suite Compliance