A technician is configuring a small office wireless router for a client. The client wants the network to be as secure as possible while still allowing employees to connect easily with a pre-shared key. The router supports WPA2, WPA3, WPA, and WEP. Which security protocol should the technician select?
Trap 1: WPA2-PSK with AES
WPA2-PSK with AES is secure and widely supported, but it is not the most secure option available on this router. WPA3-Personal improves upon WPA2 by using Simultaneous Authentication of Equals (SAE), which provides stronger protection against offline dictionary attacks. Since the router supports WPA3, selecting WPA2 would leave the network less secure than possible.
Trap 2: WPA-PSK with TKIP
WPA-PSK with TKIP is an older security protocol that is deprecated due to vulnerabilities in TKIP. It is less secure than WPA2 and WPA3 and should not be used when stronger options are available. The scenario requires the most secure configuration, so WPA with TKIP is inappropriate.
Trap 3: WEP with 128-bit key
WEP is an outdated and insecure protocol that can be easily cracked. Even with a 128-bit key, it does not provide adequate security for a business network. The scenario calls for the most secure option, so WEP is clearly wrong. It should never be used when WPA2 or WPA3 is available.
- A
WPA2-PSK with AES
Why it fails: WPA2-PSK with AES is secure and widely supported, but it is not the most secure option available on this router. WPA3-Personal improves upon WPA2 by using Simultaneous Authentication of Equals (SAE), which provides stronger protection against offline dictionary attacks. Since the router supports WPA3, selecting WPA2 would leave the network less secure than possible.
- B
WPA-PSK with TKIP
Why it fails: WPA-PSK with TKIP is an older security protocol that is deprecated due to vulnerabilities in TKIP. It is less secure than WPA2 and WPA3 and should not be used when stronger options are available. The scenario requires the most secure configuration, so WPA with TKIP is inappropriate.
- C
WPA3-Personal
WPA3-Personal is the most secure option among those listed and is supported by the router. It uses SAE (Simultaneous Authentication of Equals) to provide forward secrecy and resistance to offline dictionary attacks, which WPA2-PSK lacks. It still allows easy connection with a pre-shared key, satisfying the client's requirement. Therefore, it is the best choice.
- D
WEP with 128-bit key
Why it fails: WEP is an outdated and insecure protocol that can be easily cracked. Even with a 128-bit key, it does not provide adequate security for a business network. The scenario calls for the most secure option, so WEP is clearly wrong. It should never be used when WPA2 or WPA3 is available.