Courseiva
Networking →mediumMultiple Choice

220-1101 Networking Practice Question

A network technician is deploying a new wireless access point in a warehouse. The AP will serve many devices that need strong security and support for simultaneous connections without interference from neighboring networks. The technician configures the AP to operate on the 5 GHz band and enables WPA3-Personal. Which security protocol and encryption standard does WPA3-Personal use for authentication and encryption?

⚠ Common exam trap

The trap here is assuming WPA3-Personal still uses PSK or that it supports TKIP, when it actually uses SAE and AES-CCMP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA3-Personal uses SAE (Simultaneous Authentication of Equals) for authentication and AES-CCMP for encryption.

WPA3-Personal introduces SAE to replace the pre-shared key (PSK) method used in WPA2-Personal, providing stronger protection against offline dictionary attacks and forward secrecy. Encryption remains AES-CCMP, ensuring robust data protection. In a warehouse environment with many devices and potential interference, WPA3-Personal on 5 GHz offers both security and performance. The correct answer reflects the standard's authentication and encryption mechanisms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    WPA3-Personal uses SAE (Simultaneous Authentication of Equals) for authentication and AES-CCMP for encryption.

    Why this is correct

    WPA3-Personal replaces WPA2's PSK with SAE (Simultaneous Authentication of Equals), which provides forward secrecy and resistance to offline dictionary attacks. Encryption remains AES-CCMP, though WPA3 also supports GCMP for higher speeds. In a warehouse with many devices, SAE ensures each session is secure even if a password is compromised later. This is the correct standard for WPA3-Personal.

  • ✗

    WPA3-Personal uses 802.1X/EAP for authentication and AES-CCMP for encryption.

    Why it's wrong here

    802.1X/EAP is used in WPA3-Enterprise, not WPA3-Personal. WPA3-Personal is designed for environments without a RADIUS server, using SAE instead of 802.1X. While AES-CCMP is correct for encryption, the authentication method is wrong. In a warehouse without centralized authentication, 802.1X would require additional infrastructure. Therefore, this option misidentifies the authentication method.

  • ✗

    WPA3-Personal uses PSK for authentication and TKIP for encryption.

    Why it's wrong here

    PSK with TKIP is used in WPA (and optionally WPA2), not WPA3. TKIP is deprecated and insecure, and WPA3 does not allow TKIP. Using PSK would leave the network vulnerable to offline dictionary attacks, which WPA3 specifically mitigates. In a warehouse with many devices, TKIP would also limit throughput. Thus, this combination is incorrect for WPA3-Personal.

  • ✗

    WPA3-Personal uses SAE for authentication and TKIP for encryption.

    Why it's wrong here

    While SAE is correct for WPA3-Personal authentication, TKIP is not used for encryption in WPA3. TKIP is an older, deprecated protocol with known vulnerabilities. WPA3 mandates AES-CCMP or GCMP. Using TKIP would weaken security and may not be supported by WPA3-certified devices. Thus, this combination is invalid for WPA3-Personal.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

Go deeper

Related to this question

About these practice questions

Courseiva writes every 220-1101 question from scratch — 896 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.