A network administrator is migrating a corporate wireless network to WPA3-Enterprise to enhance access control and audit capabilities for individual staff members. During deployment, a junior technician suggests configuring Simultaneous Authentication of Equals (SAE) across the wireless access points to simplify onboarding without integrating the organization's existing RADIUS server. Which of the following best explains why this recommendation fails to meet the enterprise security requirement?
- Simultaneous Authentication of Equals (SAE) is designed for WPA3-Personal and relies on a shared passphrase, failing to provide individual user authentication and centralized 802.1X accounting.Cevap
- BSimultaneous Authentication of Equals (SAE) mandates 192-bit GCMP encryption, which cannot be processed by standard 802.1X authentication servers.
- CSimultaneous Authentication of Equals (SAE) operates exclusively with TACACS+ protocols, preventing standard Layer 2 EAP packet encapsulation on wireless access points.
- DSimultaneous Authentication of Equals (SAE) disables Protected Management Frames (PMF), exposing wireless management frames to spoofed deauthentication attacks.
Cevap
Simultaneous Authentication of Equals (SAE) is designed for WPA3-Personal and relies on a shared passphrase, failing to provide individual user authentication and centralized 802.1X accounting.
WPA3-Enterprise requires IEEE 802.1X authentication using EAP methods backed by a RADIUS server to verify each user individually. Simultaneous Authentication of Equals (SAE) is a key exchange mechanism designed specifically for WPA3-Personal to secure passphrase-based networks, making it incapable of delivering individual user identification or centralized AAA accounting.
Adım Adım Çözüm
Anahtar Kavram
WPA3 Personal vs Enterprise Authentication Architecture