CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography
A security team is evaluating wireless security for a corporate network. They want to implement the strongest current encryption standard for Wi-Fi. Which of the following should they choose?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA3 with SAE
WPA3 is the latest Wi-Fi security standard, offering stronger encryption with SAE (Simultaneous Authentication of Equals) and replacing WPA2.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WEP with 128-bit key
Why it's wrong here
WEP, even with a 128-bit key, is fundamentally insecure due to critical design flaws, primarily its weak Initialization Vector (IV) management and reliance on the RC4 stream cipher. The short IVs are often reused, making it highly susceptible to statistical attacks that can quickly recover the WEP key. This vulnerability allows attackers to decrypt traffic and gain unauthorized network access, rendering it completely unsuitable for any corporate environment.
- ✗
WPA2 with CCMP
Why it's wrong here
While WPA2 with CCMP (Counter Mode with Cipher Block Chaining Message Authentication Code Protocol) provides robust encryption and integrity, it is not the most current or secure standard available for new deployments. Although the KRACK vulnerability was patched, WPA2 lacks protections against offline dictionary attacks in its Personal mode and does not offer forward secrecy by default. Therefore, while still widely used, it is superseded by WPA3's enhanced security features.
- ✗
802.1X with EAP-TLS
Why it's wrong here
802.1X with EAP-TLS is an authentication framework that provides strong, certificate-based mutual authentication for network access, but it is not a wireless encryption standard itself. Instead, 802.1X defines how authentication occurs, typically leveraging protocols like WPA2 or WPA3 to handle the actual data encryption and integrity after successful authentication. This option addresses authentication but not the underlying wireless encryption protocol, which is the primary focus for overall wireless security.
- ✓
WPA3 with SAE
Why this is correct
WPA3 with SAE (Simultaneous Authentication of Equals) is the most secure Wi-Fi standard, offering significant improvements over its predecessors. SAE provides a more robust key establishment protocol that protects against offline dictionary attacks and ensures forward secrecy, meaning past session keys cannot be compromised even if the master key is later discovered. Furthermore, WPA3 enhances security for public networks through Opportunistic Wireless Encryption (OWE), providing individualized data encryption.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.