A security engineer is reviewing the WLAN configuration of a small business that uses WPA2-Personal. The owner wants to raise resistance to offline dictionary attacks against the preshared key without replacing all client hardware. Which two changes best accomplish this goal? (Choose two.)
WPA3-SAE replaces the PSK four-way handshake with a Dragonfly-based exchange that provides forward secrecy and resists passive offline dictionary attacks. An eavesdropper cannot capture a handshake and test candidate passphrases offline against it. This directly raises resistance to dictionary attacks, and WPA3-capable hardware can often be enabled through firmware or a controller profile update rather than a full replacement.
Why this answer
Offline dictionary attacks against WPA2-Personal succeed by deriving the PMK from a guessable passphrase and testing it against a captured handshake. Migrating to WPA3-SAE removes that offline attack path, and using a long random passphrase increases entropy so any captured material is impractical to crack. The two measures reinforce each other.
Exam trap
The trap here is assuming that hiding the SSID or enabling management frame protection prevents handshake capture, when neither changes the entropy of the preshared key or the offline attack model.