A company is deploying a new wireless network for employee devices and wants to use the most secure encryption method currently available for WPA2/3. Which encryption standard should be used?
AES (Advanced Encryption Standard) is the current industry standard for strong symmetric-key encryption, adopted by the U.S. government and widely used globally. It provides robust confidentiality and integrity for wireless networks, forming the cryptographic backbone of modern Wi-Fi security protocols like WPA2 and WPA3. Its strength against known attacks makes it the recommended choice for securing sensitive employee data in new deployments.
Why this answer
AES (Advanced Encryption Standard) is the most secure encryption method available for WPA2 and WPA3. WPA2 mandates AES-CCMP, and WPA3 uses AES-GCMP, both of which are based on the AES block cipher, providing strong confidentiality and integrity. This makes AES the correct choice for the highest security in modern Wi-Fi deployments.
Exam trap
The N10-009 exam often tests the misconception that TKIP is acceptable for WPA2 security, but the trap is that WPA2 mandates AES-CCMP for certification, and TKIP is only a backward-compatible option that should never be used in a secure deployment.
Why the other options are wrong
WEP is an outdated encryption standard with known vulnerabilities, easily cracked, and is not considered secure for modern WPA2/3 networks.
When would these options actually be correct?
A question asking about legacy wireless security for older devices that only support WEP, or a scenario where maximum compatibility with very old hardware is required despite low security.
TKIP would be correct in a question asking for backward compatibility with legacy devices that do not support AES, or in a scenario describing a mixed-mode WPA/WPA2 network where TKIP is used as a fallback for older clients.
DES would be correct if the question asked about legacy encryption standards for securing data at rest, such as in a scenario involving older systems that require DES for compatibility with legacy hardware or software.
Why candidates pick the wrong answer
Candidates may confuse WEP with WPA or think it is still acceptable because it was once the standard, or they may misremember the acronym as a valid encryption method.
Candidates may confuse TKIP as a secure option because it was part of the original WPA standard and is still supported in some configurations, but they overlook that AES is mandatory for WPA2/3 security.
Candidates may confuse DES with AES due to similar acronyms or mistakenly think DES is a wireless encryption standard because it is a well-known encryption algorithm, even though it is not used in Wi-Fi security.