ISC2 CC Network Security Practice Question
A security administrator is configuring a wireless network for a small office. The requirement is to use a protocol that provides strong encryption and authentication, and that is resistant to offline dictionary attacks on captured handshakes. Which protocol should be selected?
⚠ Common exam trap
The trap here is assuming WPA2-PSK is sufficient because it is widely used, when its four-way handshake still permits offline dictionary attacks on weak passphrases.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Wi-Fi Protected Access 3 (WPA3) with Simultaneous Authentication of Equals (SAE)
WPA3 with SAE is designed to replace WPA2-PSK's vulnerable four-way handshake with a mutually authenticated exchange that resists offline dictionary attacks. It also provides stronger encryption through the use of SAE and, in WPA3-Personal, forward secrecy. The other options either lack strong encryption or remain susceptible to offline attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Open authentication with Captive Portal
Why it's wrong here
Open authentication provides no encryption or authentication at the link layer; a captive portal only controls access at the application layer after association. Traffic over the air can be sniffed, and there is no protection against offline attacks because there is no cryptographic handshake. This fails both the encryption and authentication requirements.
- ✗
Wi-Fi Protected Access 2 (WPA2) with Pre-Shared Key (PSK)
Why it's wrong here
WPA2-PSK uses a pre-shared key and a four-way handshake that can be captured and attacked offline by guessing the passphrase. While stronger than WEP, it remains susceptible to offline dictionary attacks if the passphrase is weak. Thus it does not meet the requirement of being resistant to such attacks without additional measures like a strong, high-entropy passphrase.
- ✓
Wi-Fi Protected Access 3 (WPA3) with Simultaneous Authentication of Equals (SAE)
Why this is correct
WPA3 introduces SAE, a Dragonfly handshake that provides forward secrecy and resists offline dictionary attacks. Even if an attacker captures the handshake, they cannot perform an offline guessing attack; they must interact with the network for each guess, which is detectable and rate-limited. This directly satisfies the requirement for strong encryption and resistance to offline attacks.
- ✗
Wired Equivalent Privacy (WEP)
Why it's wrong here
WEP uses RC4 with a short, static initialization vector and weak key scheduling, making it trivially broken with readily available tools. It does not provide strong authentication and is vulnerable to offline cracking after capturing a small amount of traffic. It fails the requirement for resistance to offline dictionary attacks because its flaws allow direct key recovery.
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
PSK
A pre-shared key (PSK) is a secret string of characters shared in advance between two parties to authenticate and encrypt wireless or VPN communications.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.