Soru

Zorluk: Çok zorWireless Security Standards and Encryption Protocols

A network security architect at a high-security research institution is deploying a new wireless network to comply with National Security Agency (NSA) Commercial National Security Algorithm (CNSA) Suite standards. The compliance mandate specifies that all wireless communications must use 192-bit cryptographic strength for both data confidentiality and integrity, paired with centralized identity management. Which configuration combination on the wireless LAN controller (WLC) and authentication server satisfies all aspects of this security mandate?

  1. WPA3-Enterprise 192-bit Mode using GCMP-256 encryption cipher and 802.1X RADIUS authentication with EAP-TLSCevap
  2. B
    WPA3-Personal using Simultaneous Authentication of Equals (SAE) with GCMP-256 encryption cipher
  3. C
    WPA3-Enterprise 192-bit Mode using AES-CCMP-128 encryption cipher and TACACS+ authentication with EAP-FAST
  4. D
    WPA2-Enterprise using AES-CCMP-256 encryption cipher and 802.1X RADIUS authentication with EAP-PEAPv0/MSCHAPv2

Cevap

WPA3-Enterprise 192-bit Mode using GCMP-256 encryption cipher and 802.1X RADIUS authentication with EAP-TLS is the correct configuration.
WPA3-Enterprise 192-bit Mode is specifically designed for high-security enterprise environments (such as government, financial, and military networks) adhering to the NSA's CNSA Suite. It requires 256-bit Galois/Counter Mode Protocol (GCMP-256) for data encryption, GMAC-256 for Protected Management Frames, 384-bit Elliptic Curve Diffie-Hellman (ECDHE) key exchange, and 802.1X RADIUS authentication using EAP-TLS with digital certificates.

Adım Adım Çözüm

1
Analyze compliance requirements
Identified the need for 192-bit CNSA Suite cryptographic security (high security / government level) and centralized identity management.
CNSA Suite compliance mandates 192-bit security strength for symmetric ciphers, key exchange, and digital signatures.
2
Evaluate wireless standard and encryption cipher selection
WPA3-Enterprise 192-bit Mode utilizes 256-bit Galois/Counter Mode Protocol (GCMP-256) for data frames and Broadcast/Multicast Integrity Protocol 256-bit (BIP-GMAC-256) for Protected Management Frames (PMF).
Standard WPA2/WPA3 AES-CCMP-128 or WPA3-Personal does not satisfy 192-bit CNSA Suite requirements.
3
Evaluate authentication protocol and server selection
802.1X enterprise authentication utilizing RADIUS with EAP-TLS provides individual user credentialing backed by PKI certificates, satisfying 192-bit security requirements.
TACACS+ is an administrative protocol, while WPA3-Personal SAE relies on pre-shared passphrases without RADIUS user account integration.

Anahtar Kavram

WPA3-Enterprise 192-bit Security Mode and CNSA Suite Compliance
Bu soruyu puanla