Courseiva
easyMultiple Choice

220-1102 Practice Question: A company's IT policy requires that all wireless…

A company's IT policy requires that all wireless traffic be encrypted using the strongest available protocol. A technician is configuring a new access point that supports WPA3-SAE, WPA2-PSK with AES, and WPA2-PSK with TKIP. Which configuration meets the policy?

⚠ Common exam trap

A common misconception is that WPA2-PSK with AES is the strongest option because it uses the AES cipher, but the trap here is that the security of the authentication handshake (SAE vs. PSK) is more critical than the encryption cipher, and WPA3-SAE provides a fundamentally stronger authentication mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA3-SAE.

WPA3-SAE (Simultaneous Authentication of Equals) is the strongest available wireless encryption protocol among the options, as it replaces the pre-shared key (PSK) model with a more secure handshake that provides forward secrecy and is resistant to offline dictionary attacks. The IT policy requires the strongest available protocol, and WPA3-SAE is superior to both WPA2-PSK variants, making option C the correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPA2-PSK with TKIP.

    Why it's wrong here

    TKIP is a deprecated cipher with known weaknesses, so selecting it directly contradicts the strongest-available-protocol policy. It is tempting because TKIP preserves compatibility with very old wireless adapters, making it the right pick only when legacy clients cannot support AES-CCMP at all.

  • ✗

    WPA2-PSK with AES.

    Why it's wrong here

    WPA2-PSK with AES uses CCMP, which is secure but superseded by WPA3-SAE's simultaneous authentication of equals, so it does not satisfy the strongest-protocol requirement. It is tempting because AES-CCMP remains widely supported and is the correct choice when clients cannot negotiate WPA3.

  • ✓

    WPA3-SAE.

    Why this is correct

    WPA3-SAE uses Simultaneous Authentication of Equals, a Dragonfly handshake providing forward secrecy and resistance to offline dictionary attacks, unlike WPA2-PSK's pre-shared key exchange. It is the strongest protocol the access point supports, satisfying the policy's requirement for the strongest available encryption.

  • ✗

    A mixed mode of WPA2 and WPA3.

    Why it's wrong here

    Mixed mode still permits WPA2-PSK associations, so clients can negotiate AES-CCMP rather than WPA3-SAE, failing the strongest-protocol requirement. It is tempting because mixed mode maintains backwards compatibility with older devices, which is the correct choice when legacy hardware must connect, but not here.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.