CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography
A security engineer wants to ensure that a wireless network uses the most secure encryption available. Which of the following should be configured on the access point?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA3
WPA3 is the latest Wi-Fi security standard, providing stronger encryption (GCMP-256) and protection against dictionary attacks via SAE.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WEP
Why it's wrong here
WEP (Wired Equivalent Privacy) is an outdated wireless security protocol that should never be used in any modern network. Its fundamental design flaws, including a small, static initialization vector (IV) and weak key management with the RC4 stream cipher, make it highly susceptible to various attacks. Attackers can easily capture enough packets to deduce the WEP key in minutes using tools like Aircrack-ng, rendering any transmitted data completely insecure. This protocol offers virtually no protection against contemporary threats.
- ✓
WPA3
Why this is correct
WPA3 (Wi-Fi Protected Access 3) is the latest and most robust security standard for wireless networks, offering significant enhancements over its predecessors. It introduces Simultaneous Authentication of Equals (SAE) as a more secure key exchange protocol, replacing the vulnerable Pre-Shared Key (PSK) exchange in WPA2 and providing stronger protection against dictionary attacks. WPA3 also enhances privacy in open networks with Opportunistic Wireless Encryption (OWE) and ensures forward secrecy, making it the recommended choice for maximum security and resilience against evolving threats.
- ✗
WPA2 with TKIP
Why it's wrong here
WPA2 with TKIP (Temporal Key Integrity Protocol) is a legacy encryption method designed as an interim solution to replace WEP without requiring new hardware. While an improvement over WEP, TKIP inherits some of WEP's cryptographic weaknesses and is known to be susceptible to various attacks, including key recovery and message injection. Its use significantly degrades the overall security posture of a wireless network, making it unsuitable for environments requiring strong data protection and compliance with current security standards.
- ✗
WPA2 with AES
Why it's wrong here
WPA2 with AES (Advanced Encryption Standard) using CCMP (Counter Mode with Cipher Block Chaining Message Authentication Code Protocol) provides strong cryptographic protection and was the industry standard for many years. While significantly more secure than WEP or WPA2-TKIP, WPA2-AES remains vulnerable to offline dictionary attacks against its Pre-Shared Key (PSK) handshake, especially with weak passphrases. Furthermore, it lacks the enhanced forward secrecy and robust key establishment mechanisms offered by WPA3, making it no longer the strongest available option for wireless security.
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.