Courseiva
Communication and Network SecuritymediumMultiple ChoiceObjective-mapped

CISSP Communication and Network Security Practice Question

An organization is migrating from WPA2 to WPA3 for its wireless network. Which improvement does WPA3 provide over WPA2?

⚠ Common exam trap

Test-takers frequently confuse WPA3's mandatory use of SAE with the older WPA2-PSK handshake, and mistakenly think WPA3 still supports TKIP or WPS, or that it only works in Enterprise mode, when in fact SAE is the core personal mode enhancement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Simultaneous Authentication of Equals (SAE) providing forward secrecy

WPA3 replaces WPA2's Pre-Shared Key (PSK) handshake with Simultaneous Authentication of Equals (SAE), defined in IEEE 802.11-2016 and RFC 7664. SAE uses a Dragonfly key exchange based on discrete logarithm cryptography, which provides forward secrecy: even if an attacker captures the handshake and later obtains the pre-shared key, they cannot decrypt past session traffic. This eliminates the vulnerability to offline dictionary attacks that plagued WPA2-PSK.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use of TKIP for backward compatibility

    Why it's wrong here

    TKIP (Temporal Key Integrity Protocol) was a stopgap security protocol introduced with WPA to address vulnerabilities in WEP, but it itself contains known cryptographic weaknesses and is considered insecure. WPA3 explicitly deprecates TKIP and mandates stronger cryptographic algorithms, such as CCMP (used in WPA2) and GCMP (used in WPA3), to ensure robust security. Therefore, WPA3 does not support TKIP for backward compatibility; its inclusion would fundamentally undermine the enhanced security objectives of the standard.

  • Mandatory use of WPS for easy setup

    Why it's wrong here

    Wi-Fi Protected Setup (WPS) is a legacy feature designed for simplified device connection, primarily through PIN-based authentication or push-button methods. However, WPS has well-documented security vulnerabilities, particularly the susceptibility of its PIN method to brute-force attacks, which can compromise the network's pre-shared key. WPA3 intentionally excludes WPS to eliminate these known security risks and enforce more secure authentication mechanisms, making its mandatory use contradictory to WPA3's design principles.

  • Simultaneous Authentication of Equals (SAE) providing forward secrecy

    Why this is correct

    Simultaneous Authentication of Equals (SAE), also known as Dragonfly Key Exchange, is the foundational key exchange protocol for WPA3-Personal mode. SAE significantly enhances security by providing robust protection against offline dictionary attacks, even if a weak passphrase is used, through its password-authenticated key exchange (PAKE) mechanism. Crucially, SAE also delivers forward secrecy, meaning that if the network's long-term secret key is ever compromised, past session traffic remains encrypted and secure because unique session keys are not derivable from the master key alone.

  • Support for 802.1X only, no personal mode

    Why it's wrong here

    WPA3 is designed to cater to both personal and enterprise environments, offering distinct modes for each. WPA3-Personal utilizes Simultaneous Authentication of Equals (SAE) for robust password-based authentication, suitable for home and small office networks. Conversely, WPA3-Enterprise leverages IEEE 802.1X, integrating with RADIUS servers for stronger, certificate-based or credential-based authentication, which is essential for larger organizations requiring centralized user management and advanced security policies. Therefore, stating WPA3 supports 802.1X only is incorrect, as it fully supports both operational modes.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.