Courseiva
Switching and Network AccessmediumMultiple SelectObjective-mapped

CCNA Switching and Network Access Practice Question

Which two statements accurately describe WPA2 and WPA3 in wireless security?

⚠ Common exam trap

Avoid assuming WPA3 is limited to specific frequency bands or that WPA2 offers superior security features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Both are wireless security standards used to help protect WLAN access and traffic.

WPA2 and WPA3 are wireless security standards used to protect WLAN access and traffic. In practical terms, both are associated with securing wireless communication, but WPA3 is generally positioned as the newer standard with security improvements over WPA2. The key idea at CCNA level is recognizing them as WLAN security standards rather than confusing them with SSIDs, controllers, or radio bands. You do not need deep protocol internals here. You need the role and relative positioning right.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Both are wireless security standards used to help protect WLAN access and traffic.

    Why this is correct

    WPA2 and WPA3 are security protocols that provide authentication and encryption for wireless LANs. WPA2 relies on AES-CCMP for data confidentiality, while WPA3 uses AES-GCMP (with 128-bit keys) and mandates Protected Management Frames to strengthen integrity. They both secure the communications between a wireless client and an access point, thereby protecting WLAN access and traffic from eavesdropping, tampering, and unauthorized use.

  • WPA3 is the newer standard relative to WPA2.

    Why this is correct

    WPA3 is a newer generation of the Wi-Fi Protected Access family, introduced in 2018 by the Wi-Fi Alliance to replace WPA2. It uses Simultaneous Authentication of Equals (SAE) instead of the Pre-Shared Key (PSK) method found in WPA2, providing stronger resistance to offline dictionary attacks and offering forward secrecy. As a newer standard, WPA3 also adds support for 192-bit security suites and easier configuration of IoT devices without a display.

  • Both are names for specific 802.11 radio frequencies.

    Why it's wrong here

    WPA2 and WPA3 are not radio frequencies; they are security standards defined above the 802.11 physical layer. Actual 802.11 radio frequencies include 2.4 GHz, 5 GHz, and 6 GHz bands, which are determined by the PHY layer specifications such as 802.11ac or 802.11ax. WPA2 and WPA3 can operate over any of these frequency bands, so they are orthogonal to the radio spectrum and do not designate specific frequencies themselves.

    When this WOULD be correct

    If the exam question asked about the naming conventions of wireless standards and their association with specific frequency bands, then this option could be correct if it referred to a hypothetical scenario where WPA2 and WPA3 were misinterpreted as frequency designations.

  • WPA2 and WPA3 are types of trunk ports.

    Why it's wrong here

    Trunk ports are a Layer 2 switching feature used to carry traffic for multiple VLANs over a single physical link, typically using IEEE 802.1Q tagging. WPA2 and WPA3, in contrast, are wireless security standards that operate in the data link layer of the 802.11 protocol stack for authentication and encryption between clients and access points. They have absolutely no relation to switch port modes or VLAN trunking, which is a wired networking concept.

    When this WOULD be correct

    If the exam question specifically asked about types of network configurations or VLAN implementations, a statement about WPA2 and WPA3 being types of trunk ports could be correct in a hypothetical context where the question mistakenly conflates wireless security with network topology.

  • WPA3 eliminates the need for SSIDs.

    Why it's wrong here

    An SSID (Service Set Identifier) is the broadcast network name that allows wireless clients to identify and associate with a specific WLAN. WPA3 does not remove or replace SSIDs because the SSID is part of the 802.11 beacon and probe mechanisms, independent of the security standard in use. Even when WPA3 is enabled, the access point still advertises an SSID; WPA3 just secures the connection after the client chooses and associates to that network.

    When this WOULD be correct

    If the exam question were to ask about a hypothetical future wireless security standard that integrates SSID-less connections, then this option could be correct. For example, a question might state, 'What advancements in wireless security protocols eliminate the need for SSIDs?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

Both are wireless security standards used to help protect WLAN access and traffic.Correct answer

Why this is correct

WPA2 and WPA3 are security protocols that provide authentication and encryption for wireless LANs. WPA2 relies on AES-CCMP for data confidentiality, while WPA3 uses AES-GCMP (with 128-bit keys) and mandates Protected Management Frames to strengthen integrity. They both secure the communications between a wireless client and an access point, thereby protecting WLAN access and traffic from eavesdropping, tampering, and unauthorized use.

Both are names for specific 802.11 radio frequencies.Wrong answer — click to see why

Why this is wrong here

WPA2 and WPA3 are security protocols, not radio frequencies. 802.11 radio frequencies refer to bands like 2.4 GHz and 5 GHz, which are unrelated to security standards.

★ When this WOULD be the correct answer

If the exam question asked about the naming conventions of wireless standards and their association with specific frequency bands, then this option could be correct if it referred to a hypothetical scenario where WPA2 and WPA3 were misinterpreted as frequency designations.

Why candidates choose this

Students might confuse the '802.11' in Wi-Fi standards with security protocols, or mistakenly think that WPA versions correspond to different frequency bands.

WPA2 and WPA3 are types of trunk ports.Wrong answer — click to see why

Why this is wrong here

Trunk ports are a concept in switched networks for carrying multiple VLANs, typically using 802.1Q tagging. WPA2 and WPA3 have nothing to do with switch port configuration.

★ When this WOULD be the correct answer

If the exam question specifically asked about types of network configurations or VLAN implementations, a statement about WPA2 and WPA3 being types of trunk ports could be correct in a hypothetical context where the question mistakenly conflates wireless security with network topology.

Why candidates choose this

The term 'trunk' might be confused with 'wireless' due to similar-sounding terminology, or a student might incorrectly associate security with port types.

WPA3 eliminates the need for SSIDs.Wrong answer — click to see why

Why this is wrong here

WPA3 does not eliminate the need for SSIDs; SSIDs are still required to identify and differentiate wireless networks. WPA3 focuses on authentication and encryption, not network identification.

★ When this WOULD be the correct answer

If the exam question were to ask about a hypothetical future wireless security standard that integrates SSID-less connections, then this option could be correct. For example, a question might state, 'What advancements in wireless security protocols eliminate the need for SSIDs?'

Why candidates choose this

A student might think that newer security standards remove older concepts like SSIDs, or confuse SSID with security features like pre-shared keys.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.