CCNA Network Infrastructure and Connectivity Practice Question
Which statement correctly describes a feature of WPA3 security in wireless LANs?
⚠ Common exam trap
Many candidates incorrectly assume WPA3 universally uses GCMP-256 encryption, confusing the optional enterprise mode with the baseline WPA3-Personal requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA3 introduces Simultaneous Authentication of Equals (SAE) to resist offline dictionary attacks.
WPA3 introduces Simultaneous Authentication of Equals (SAE), which uses a Dragonfly key exchange to resist offline dictionary attacks and provide forward secrecy. Option A is wrong because WPA3 does not use or support TKIP encryption; it mandates AES. Option C is wrong because WPA3-Personal uses SAE, not 802.1X/EAP. Option D is wrong because GCMP-256 is only mandatory in the optional WPA3-Enterprise 192-bit security mode, not across all WPA3 deployments; standard WPA3-Personal uses AES-GCMP with 128-bit keys. Option E is wrong because WPA3 requires Protected Management Frames (PMF) by default, unlike WPA2.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPA3 uses TKIP encryption for backward compatibility with legacy devices.
Why it's wrong here
WPA3 does not use TKIP under any circumstances; TKIP is a legacy WPA/WPA2 cipher that is deprecated because of known cryptographic weaknesses. The Wi-Fi Alliance explicitly forbids TKIP in WPA3-certified devices. Backward compatibility with older clients is handled through transition mode, where the AP can simultaneously support WPA2 and WPA3, not by falling back to TKIP.
- ✓
WPA3 introduces Simultaneous Authentication of Equals (SAE) to resist offline dictionary attacks.
Why this is correct
WPA3 replaces the pre-shared key (PSK) four-way handshake with the Simultaneous Authentication of Equals (SAE) protocol, also known as Dragonfly. SAE uses a secure password-authenticated key exchange that provides forward secrecy and prevents an attacker from capturing the handshake and performing offline dictionary or brute-force attacks. Even if the password is weak, each guess requires interaction with the network, greatly increasing the difficulty of compromise.
- ✗
WPA3 relies solely on 802.1X/EAP authentication for both personal and enterprise modes.
Why it's wrong here
WPA3 Personal mode does not use 802.1X/EAP at all; it authenticates users with a passphrase via SAE. The 802.1X/EAP framework is reserved for WPA3 Enterprise mode, where it supports multiple user identities and an authentication server. Thus, the statement incorrectly conflates the two modes and ignores SAE as the mandatory Personal-mode authentication method.
- ✗
WPA3 mandates the use of GCMP-256 encryption for enhanced security.
Why it's wrong here
WPA3 does not mandate GCMP-256 encryption across all deployments. The baseline WPA3 specification requires CCMP-128 (AES) as the minimum security suite. GCMP-256 is used in the optional WPA3-Enterprise 192-bit security mode, but it is not a universal mandate. Therefore, saying WPA3 mandates GCMP-256 overstates its use and ignores the baseline CCMP-128 requirement.
When this WOULD be correct
When configuring WPA3 on APs and clients, GCMP-256 is required for full compliance.
- ✗
WPA3 makes Protected Management Frames (PMF) optional to support older clients.
Why it's wrong here
WPA3 makes Protected Management Frames (PMF) mandatory, not optional, for all certified devices. PMF uses 802.11w mechanisms to encrypt management frames, preventing attackers from forging deauthentication and disassociation frames to disrupt clients. Older clients that cannot support PMF are simply not allowed to connect in pure WPA3 networks; transition mode handles legacy devices separately.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓WPA3 introduces Simultaneous Authentication of Equals (SAE) to resist offline dictionary attacks.Correct answer▾
Why this is correct
WPA3 replaces the pre-shared key (PSK) four-way handshake with the Simultaneous Authentication of Equals (SAE) protocol, also known as Dragonfly. SAE uses a secure password-authenticated key exchange that provides forward secrecy and prevents an attacker from capturing the handshake and performing offline dictionary or brute-force attacks. Even if the password is weak, each guess requires interaction with the network, greatly increasing the difficulty of compromise.
✗WPA3 uses TKIP encryption for backward compatibility with legacy devices.Wrong answer — click to see why▾
Why this is wrong here
TKIP is an older encryption protocol that is not allowed in WPA3; using it would defeat the security improvements.
✗WPA3 relies solely on 802.1X/EAP authentication for both personal and enterprise modes.Wrong answer — click to see why▾
Why this is wrong here
This statement confuses the two modes; WPA3 Personal does not require 802.1X.
✗WPA3 mandates the use of GCMP-256 encryption for enhanced security.Wrong answer — click to see why▾
Why this is wrong here
GCMP-256 is only mandated in the optional WPA3-Enterprise 192-bit security mode; standard WPA3-Personal uses AES-GCMP with 128-bit keys.
★ When this WOULD be the correct answer
When configuring WPA3 on APs and clients, GCMP-256 is required for full compliance.
✗WPA3 makes Protected Management Frames (PMF) optional to support older clients.Wrong answer — click to see why▾
Why this is wrong here
Making PMF optional would weaken security; WPA3 enforces PMF to ensure management frame protection.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Native VLAN Security
Key term
AES
AES is a fast and secure encryption standard used worldwide to protect sensitive data by scrambling it so only authorized parties can read it.
Key term
Bit
A bit is the smallest unit of data in computing and digital communications, representing a single binary value of either 0 or 1.
About these practice questions
Courseiva writes every 200-301 question from scratch — 1,389 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.