GSEC Wireless Network Security Practice Question
A security researcher is evaluating the susceptibility of a WPA3-Personal network to offline dictionary attacks. Which statement accurately describes the resistance provided by WPA3-SAE compared to WPA2-PSK?
⚠ Common exam trap
The trap here is thinking that WPA3-SAE merely strengthens encryption or lengthens keys, when its core advantage is the Dragonfly handshake that eliminates the offline crackable hash.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA3-SAE prevents offline dictionary attacks by using a simultaneous authentication of equals handshake that does not expose a crackable hash.
WPA3-SAE employs the Dragonfly handshake, which provides forward secrecy and prevents offline dictionary attacks by ensuring that the password is not exposed in a crackable form. An attacker must interact with the AP for each guess, making brute-force impractical. WPA2-PSK's 4-way handshake exposes a hash that can be cracked offline. The other options mischaracterize SAE's design or confuse it with unrelated features.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPA3-SAE still allows offline dictionary attacks but requires more computational effort due to stronger encryption.
Why it's wrong here
WPA3-SAE is specifically designed to prevent offline dictionary attacks. The Dragonfly handshake ensures that each authentication attempt requires interaction with the AP, making brute-force impractical. The claim that it still allows offline attacks is incorrect. Stronger encryption alone does not address the offline attack vector; the protocol design is what provides resistance. Therefore, this statement misrepresents SAE's security properties.
- ✗
WPA3-SAE requires a captive portal to prevent offline attacks, as it does not encrypt management frames.
Why it's wrong here
WPA3-SAE does not require a captive portal; it is a standalone authentication method. It also optionally supports Protected Management Frames (PMF) which can encrypt certain management frames, but PMF is not required for SAE's resistance to offline attacks. The resistance comes from the Dragonfly handshake. This option confuses unrelated features and incorrectly states a requirement that does not exist.
- ✓
WPA3-SAE prevents offline dictionary attacks by using a simultaneous authentication of equals handshake that does not expose a crackable hash.
Why this is correct
WPA3-SAE uses a Dragonfly handshake that provides forward secrecy and resists offline dictionary attacks. Even if an attacker captures the handshake, they cannot perform an offline brute-force because the exchange does not reveal a password-derived hash that can be tested without interacting with the AP. This is a key improvement over WPA2-PSK, which is vulnerable to offline cracking.
- ✗
WPA3-SAE uses the same 4-way handshake as WPA2-PSK but with a longer key, making offline attacks infeasible.
Why it's wrong here
WPA3-SAE does not use the same 4-way handshake as WPA2-PSK. It uses the Dragonfly handshake for authentication and key establishment, followed by a 4-way handshake for key confirmation. The security improvement comes from the SAE exchange, not from a longer key. Simply lengthening the key would not prevent offline attacks if the handshake remained vulnerable. This option inaccurately describes the protocol.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.