hardMultiple Choice
220-1102 Practice Question: A security incident occurs where an attacker…
A security incident occurs where an attacker captures the 4-way handshake of a WPA2-PSK network and successfully cracks the passphrase offline. The technician is tasked with preventing this type of attack in the future. Which protocol should the technician implement?
⚠ Common exam trap
A common misconception is that simply increasing passphrase length or switching to enterprise authentication prevents offline cracking of the 4-way handshake, when in fact only a protocol change to SAE (WPA3) eliminates the offline dictionary attack vector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA3-SAE.
WPA3-SAE (Simultaneous Authentication of Equals) replaces the pre-shared key (PSK) model with a password-authenticated key exchange that is resistant to offline dictionary attacks. Unlike WPA2-PSK, which transmits a hash of the password in the 4-way handshake that can be captured and cracked offline, SAE uses a zero-knowledge proof protocol that prevents an attacker from deriving the password from captured handshake data, even if they have the full handshake.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPA2-PSK with a longer passphrase.
Why it's wrong here
Lengthening the passphrase only raises offline cracking cost; the captured 4-way handshake still yields a crackable PMKID/hash because WPA2-PSK derives keys from the passphrase itself. WPA3-SAE replaces this with the Dragonfly handshake, defeating offline dictionary attacks. Longer passphrases suit environments where WPA3 hardware is unavailable and passphrase entropy is the only control.
- ✓
WPA3-SAE.
Why this is correct
WPA3-SAE replaces the WPA2-PSK four-way handshake's offline-crackable exchange with a simultaneous authentication of equals, a dragonfly handshake providing forward secrecy and resisting offline dictionary attacks. This directly prevents the captured-handshake cracking described, satisfying the requirement to stop that attack type.
- ✗
WPA2-Enterprise with PEAP-MSCHAPv2.
Why it's wrong here
PEAP-MSCHAPv2 still derives keys from credentials, so captured handshakes remain crackable offline if the passphrase is weak; it does not defeat offline cracking. WPA3-SAE with forward secrecy prevents this. WPA2-Enterprise tempts because it removes shared passphrases, but MSCHAPv2 authentication does not stop the attack.
- ✗
WPA2-PSK with TKIP.
Why it's wrong here
TKIP is a deprecated cipher that still derives keys from a passphrase, so the captured handshake remains crackable offline; it also caps speeds at 54 Mbps. It is tempting because TKIP was designed to replace WEP, and would suit legacy hardware that cannot support AES-CCMP.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Pre-shared Key
A secret password or passphrase that two devices share beforehand to prove they are allowed to connect and communicate securely.
Key term
PSK
A pre-shared key (PSK) is a secret string of characters shared in advance between two parties to authenticate and encrypt wireless or VPN communications.
About these practice questions
This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.