A network administrator is designing a wireless deployment for a corporate branch office. Security policy mandates individual user accountability, centralized credential management using an existing 802.1X RADIUS infrastructure, and enterprise-grade encryption. A junior technician proposes deploying WPA3-Personal with Simultaneous Authentication of Equals (SAE) to avoid the administrative overhead of deploying and managing digital certificates on client devices. Which of the following best explains why the technician's proposal fails to satisfy the organizational security compliance baseline?
- WPA3-Personal utilizes Simultaneous Authentication of Equals (SAE) with a shared password, which does not provide individual user authentication or integrate with 802.1X RADIUS servers.Cevap
- BWPA3-Personal automatically relays passphrase authentication requests to RADIUS servers but forces the network to use legacy TKIP encryption ciphers.
- CCentralized 802.1X user authentication requires TACACS+ infrastructure rather than RADIUS servers when authenticating wireless clients.
- DWPA3-Personal enables individual user auditing but is vulnerable to offline dictionary attacks due to its reliance on WPA2 four-way handshakes.
Cevap
WPA3-Personal utilizes Simultaneous Authentication of Equals (SAE) with a shared password, which does not provide individual user authentication or integrate with 802.1X RADIUS servers.
The requirement for individual user accountability and 802.1X RADIUS integration necessitates WPA3-Enterprise. WPA3-Personal uses Simultaneous Authentication of Equals (SAE), which protects shared passphrases against dictionary attacks but still relies on a common secret among all users, rendering it incapable of providing individual user authentication or communicating with an 802.1X RADIUS server.
Adım Adım Çözüm
Anahtar Kavram
WPA3-Personal vs. WPA3-Enterprise Authentication Mechanics