Soru

Zorluk: OrtaWireless Security Standards and Encryption Protocols

A security analyst is auditing a wireless network transition from WPA2-Personal to WPA3-Personal across several satellite offices. The goal is to support modern WPA3 security enhancements while maintaining temporary backward compatibility for legacy WPA2 devices. Which TWO of the following configuration settings or protocols are required to properly achieve this deployment? (Select TWO)

  1. Enable WPA3 Transition Mode to allow legacy WPA2-PSK clients and WPA3 SAE clients to connect to the same SSID.Cevap
  2. B
    Configure an 802.1X RADIUS server to distribute individual SAE passphrase scalars to authenticating clients.
  3. Set Protected Management Frames (PMF) to required or capable to safeguard management traffic against spoofing.Cevap
  4. D
    Integrate TACACS+ accounting services to encrypt the initial 4-way handshake key generation parameters.

Cevap

The correct requirements are enabling WPA3 Transition Mode for dual-protocol support and configuring Protected Management Frames (PMF) to secure wireless management frames.
Deploying WPA3-Personal in an environment with legacy clients requires WPA3 Transition Mode so that WPA2-PSK clients and WPA3-SAE clients can connect to the same wireless network. Additionally, Protected Management Frames (PMF / IEEE 802.11w) must be enabled because PMF is a required security baseline under the WPA3 standard to stop frame spoofing attacks.

Adım Adım Çözüm

1
Determine the mechanism for supporting legacy WPA2-Personal devices alongside WPA3-Personal devices.
Identify WPA3 Transition Mode as the standard feature allowing WPA2-PSK and WPA3-SAE clients on a single SSID.
Transition mode provides a seamless migration path without requiring separate SSIDs for legacy and modern clients.
2
Identify mandatory WPA3 security controls for frame integrity.
Select Protected Management Frames (PMF / IEEE 802.11w).
WPA3 standards mandate PMF to prevent common wireless attacks such as rogue deauthentication frame injection.
3
Evaluate authentication and authorization protocols in the wrong options.
Exclude RADIUS and TACACS+ options for this Personal (PSK/SAE) deployment scenario.
WPA3-Personal does not rely on centralized 802.1X RADIUS servers or TACACS+ administration systems.

Anahtar Kavram

WPA3-Personal (SAE), Transition Mode, and Mandatory PMF
Tahmini Süre:1m 30s
Bu soruyu puanla