CISSP Communication and Network Security Practice Question
An organization is migrating from WPA2 to WPA3 for its wireless network. Which improvement does WPA3 provide over WPA2?
⚠ Common exam trap
Test-takers frequently confuse WPA3's mandatory use of SAE with the older WPA2-PSK handshake, and mistakenly think WPA3 still supports TKIP or WPS, or that it only works in Enterprise mode, when in fact SAE is the core personal mode enhancement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Simultaneous Authentication of Equals (SAE) providing forward secrecy
WPA3 replaces WPA2's Pre-Shared Key (PSK) handshake with Simultaneous Authentication of Equals (SAE), defined in IEEE 802.11-2016 and RFC 7664. SAE uses a Dragonfly key exchange based on discrete logarithm cryptography, which provides forward secrecy: even if an attacker captures the handshake and later obtains the pre-shared key, they cannot decrypt past session traffic. This eliminates the vulnerability to offline dictionary attacks that plagued WPA2-PSK.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use of TKIP for backward compatibility
Why it's wrong here
TKIP (Temporal Key Integrity Protocol) was a stopgap security protocol introduced with WPA to address vulnerabilities in WEP, but it itself contains known cryptographic weaknesses and is considered insecure. WPA3 explicitly deprecates TKIP and mandates stronger cryptographic algorithms, such as CCMP (used in WPA2) and GCMP (used in WPA3), to ensure robust security. Therefore, WPA3 does not support TKIP for backward compatibility; its inclusion would fundamentally undermine the enhanced security objectives of the standard.
- ✗
Mandatory use of WPS for easy setup
Why it's wrong here
Wi-Fi Protected Setup (WPS) is a legacy feature designed for simplified device connection, primarily through PIN-based authentication or push-button methods. However, WPS has well-documented security vulnerabilities, particularly the susceptibility of its PIN method to brute-force attacks, which can compromise the network's pre-shared key. WPA3 intentionally excludes WPS to eliminate these known security risks and enforce more secure authentication mechanisms, making its mandatory use contradictory to WPA3's design principles.
- ✓
Simultaneous Authentication of Equals (SAE) providing forward secrecy
Why this is correct
Simultaneous Authentication of Equals (SAE), also known as Dragonfly Key Exchange, is the foundational key exchange protocol for WPA3-Personal mode. SAE significantly enhances security by providing robust protection against offline dictionary attacks, even if a weak passphrase is used, through its password-authenticated key exchange (PAKE) mechanism. Crucially, SAE also delivers forward secrecy, meaning that if the network's long-term secret key is ever compromised, past session traffic remains encrypted and secure because unique session keys are not derivable from the master key alone.
- ✗
Support for 802.1X only, no personal mode
Why it's wrong here
WPA3 is designed to cater to both personal and enterprise environments, offering distinct modes for each. WPA3-Personal utilizes Simultaneous Authentication of Equals (SAE) for robust password-based authentication, suitable for home and small office networks. Conversely, WPA3-Enterprise leverages IEEE 802.1X, integrating with RADIUS servers for stronger, certificate-based or credential-based authentication, which is essential for larger organizations requiring centralized user management and advanced security policies. Therefore, stating WPA3 supports 802.1X only is incorrect, as it fully supports both operational modes.
Go deeper
Related to this question
Learn chapter
Cryptography and Its Applications
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.