Courseiva
Advanced Topics: Wireless, Cloud, IoT, CryptographymediumMultiple ChoiceObjective-mapped

CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography

A security team is evaluating wireless security for a corporate network. They want to implement the strongest current encryption standard for Wi-Fi. Which of the following should they choose?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

WPA3 with SAE

WPA3 is the latest Wi-Fi security standard, offering stronger encryption with SAE (Simultaneous Authentication of Equals) and replacing WPA2.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • WEP with 128-bit key

    Why it's wrong here

    WEP, even with a 128-bit key, is fundamentally insecure due to critical design flaws, primarily its weak Initialization Vector (IV) management and reliance on the RC4 stream cipher. The short IVs are often reused, making it highly susceptible to statistical attacks that can quickly recover the WEP key. This vulnerability allows attackers to decrypt traffic and gain unauthorized network access, rendering it completely unsuitable for any corporate environment.

  • WPA2 with CCMP

    Why it's wrong here

    While WPA2 with CCMP (Counter Mode with Cipher Block Chaining Message Authentication Code Protocol) provides robust encryption and integrity, it is not the most current or secure standard available for new deployments. Although the KRACK vulnerability was patched, WPA2 lacks protections against offline dictionary attacks in its Personal mode and does not offer forward secrecy by default. Therefore, while still widely used, it is superseded by WPA3's enhanced security features.

  • 802.1X with EAP-TLS

    Why it's wrong here

    802.1X with EAP-TLS is an authentication framework that provides strong, certificate-based mutual authentication for network access, but it is not a wireless encryption standard itself. Instead, 802.1X defines how authentication occurs, typically leveraging protocols like WPA2 or WPA3 to handle the actual data encryption and integrity after successful authentication. This option addresses authentication but not the underlying wireless encryption protocol, which is the primary focus for overall wireless security.

  • WPA3 with SAE

    Why this is correct

    WPA3 with SAE (Simultaneous Authentication of Equals) is the most secure Wi-Fi standard, offering significant improvements over its predecessors. SAE provides a more robust key establishment protocol that protects against offline dictionary attacks and ensures forward secrecy, meaning past session keys cannot be compromised even if the master key is later discovered. Furthermore, WPA3 enhances security for public networks through Opportunistic Wireless Encryption (OWE), providing individualized data encryption.

About these practice questions

Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.