220-1101 Networking Practice Question
A network technician is deploying a new wireless access point in a warehouse. The AP will serve many devices that need strong security and support for simultaneous connections without interference from neighboring networks. The technician configures the AP to operate on the 5 GHz band and enables WPA3-Personal. Which security protocol and encryption standard does WPA3-Personal use for authentication and encryption?
⚠ Common exam trap
The trap here is assuming WPA3-Personal still uses PSK or that it supports TKIP, when it actually uses SAE and AES-CCMP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA3-Personal uses SAE (Simultaneous Authentication of Equals) for authentication and AES-CCMP for encryption.
WPA3-Personal introduces SAE to replace the pre-shared key (PSK) method used in WPA2-Personal, providing stronger protection against offline dictionary attacks and forward secrecy. Encryption remains AES-CCMP, ensuring robust data protection. In a warehouse environment with many devices and potential interference, WPA3-Personal on 5 GHz offers both security and performance. The correct answer reflects the standard's authentication and encryption mechanisms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
WPA3-Personal uses SAE (Simultaneous Authentication of Equals) for authentication and AES-CCMP for encryption.
Why this is correct
WPA3-Personal replaces WPA2's PSK with SAE (Simultaneous Authentication of Equals), which provides forward secrecy and resistance to offline dictionary attacks. Encryption remains AES-CCMP, though WPA3 also supports GCMP for higher speeds. In a warehouse with many devices, SAE ensures each session is secure even if a password is compromised later. This is the correct standard for WPA3-Personal.
- ✗
WPA3-Personal uses 802.1X/EAP for authentication and AES-CCMP for encryption.
Why it's wrong here
802.1X/EAP is used in WPA3-Enterprise, not WPA3-Personal. WPA3-Personal is designed for environments without a RADIUS server, using SAE instead of 802.1X. While AES-CCMP is correct for encryption, the authentication method is wrong. In a warehouse without centralized authentication, 802.1X would require additional infrastructure. Therefore, this option misidentifies the authentication method.
- ✗
WPA3-Personal uses PSK for authentication and TKIP for encryption.
Why it's wrong here
PSK with TKIP is used in WPA (and optionally WPA2), not WPA3. TKIP is deprecated and insecure, and WPA3 does not allow TKIP. Using PSK would leave the network vulnerable to offline dictionary attacks, which WPA3 specifically mitigates. In a warehouse with many devices, TKIP would also limit throughput. Thus, this combination is incorrect for WPA3-Personal.
- ✗
WPA3-Personal uses SAE for authentication and TKIP for encryption.
Why it's wrong here
While SAE is correct for WPA3-Personal authentication, TKIP is not used for encryption in WPA3. TKIP is an older, deprecated protocol with known vulnerabilities. WPA3 mandates AES-CCMP or GCMP. Using TKIP would weaken security and may not be supported by WPA3-certified devices. Thus, this combination is invalid for WPA3-Personal.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Metered Network Connections
Key term
Access Point
An access point is a device that creates a wireless local area network, usually by connecting to a wired network and broadcasting a Wi-Fi signal for computers, phones, and tablets to join.
Key term
Advanced Encryption Standard
Advanced Encryption Standard (AES) is a widely used symmetric encryption algorithm that protects electronic data by converting readable information into a scrambled format that can only be unscrambled with the correct secret key.
About these practice questions
Courseiva writes every 220-1101 question from scratch — 896 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.