Courseiva
Network Security →easyMultiple Choice

ISC2 CC Network Security Practice Question

A security administrator is configuring a wireless network for a small office. The requirement is to use a protocol that provides strong encryption and authentication, and that is resistant to offline dictionary attacks on captured handshakes. Which protocol should be selected?

⚠ Common exam trap

The trap here is assuming WPA2-PSK is sufficient because it is widely used, when its four-way handshake still permits offline dictionary attacks on weak passphrases.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Wi-Fi Protected Access 3 (WPA3) with Simultaneous Authentication of Equals (SAE)

WPA3 with SAE is designed to replace WPA2-PSK's vulnerable four-way handshake with a mutually authenticated exchange that resists offline dictionary attacks. It also provides stronger encryption through the use of SAE and, in WPA3-Personal, forward secrecy. The other options either lack strong encryption or remain susceptible to offline attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Open authentication with Captive Portal

    Why it's wrong here

    Open authentication provides no encryption or authentication at the link layer; a captive portal only controls access at the application layer after association. Traffic over the air can be sniffed, and there is no protection against offline attacks because there is no cryptographic handshake. This fails both the encryption and authentication requirements.

  • ✗

    Wi-Fi Protected Access 2 (WPA2) with Pre-Shared Key (PSK)

    Why it's wrong here

    WPA2-PSK uses a pre-shared key and a four-way handshake that can be captured and attacked offline by guessing the passphrase. While stronger than WEP, it remains susceptible to offline dictionary attacks if the passphrase is weak. Thus it does not meet the requirement of being resistant to such attacks without additional measures like a strong, high-entropy passphrase.

  • ✓

    Wi-Fi Protected Access 3 (WPA3) with Simultaneous Authentication of Equals (SAE)

    Why this is correct

    WPA3 introduces SAE, a Dragonfly handshake that provides forward secrecy and resists offline dictionary attacks. Even if an attacker captures the handshake, they cannot perform an offline guessing attack; they must interact with the network for each guess, which is detectable and rate-limited. This directly satisfies the requirement for strong encryption and resistance to offline attacks.

  • ✗

    Wired Equivalent Privacy (WEP)

    Why it's wrong here

    WEP uses RC4 with a short, static initialization vector and weak key scheduling, making it trivially broken with readily available tools. It does not provide strong authentication and is vulnerable to offline cracking after capturing a small amount of traffic. It fails the requirement for resistance to offline dictionary attacks because its flaws allow direct key recovery.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.