An organization is deploying a wireless network with WPA3-Enterprise. Which THREE of the following are features or improvements of WPA3 compared to WPA2? (Select THREE.)
Trap 1: Use of TKIP for encryption
The use of Temporal Key Integrity Protocol (TKIP) for encryption is explicitly deprecated and not supported in WPA3, as TKIP was designed as a stopgap measure for WPA to address WEP's weaknesses and has known cryptographic vulnerabilities. TKIP's design includes flaws that make it susceptible to various attacks, including key recovery and message injection, rendering it insecure for modern wireless networks. WPA3 exclusively mandates robust encryption algorithms like GCMP-256 (Galois/Counter Mode Protocol with 256-bit keys) to provide strong confidentiality and integrity.
Trap 2: Support for WEP compatibility
WPA3 explicitly drops support for Wired Equivalent Privacy (WEP) compatibility because WEP is an obsolete and fundamentally insecure encryption protocol with severe cryptographic weaknesses. WEP's vulnerabilities, such as its weak initialization vector (IV) usage and static key management, allow for trivial key recovery and data decryption by attackers using readily available tools. Maintaining compatibility would introduce critical security holes into WPA3 networks, thus its removal is essential for ensuring a secure baseline.
- A
Protected Management Frames (PMF)
WPA3 mandates the use of Protected Management Frames (PMF) to secure critical management traffic, such as deauthentication and disassociation frames, which were previously unauthenticated and unencrypted in WPA2. This protection prevents denial-of-service attacks and other vulnerabilities where an attacker could spoof management frames to disrupt client connectivity or force clients to reconnect to malicious access points. PMF ensures the integrity and confidentiality of these frames, significantly enhancing the overall robustness and resilience of the wireless network against common attacks.
- B
Forward secrecy
WPA3 incorporates forward secrecy, a cryptographic property ensuring that if a long-term secret key (like the Pairwise Master Key derived from SAE) is compromised in the future, it does not enable an attacker to decrypt previously recorded session traffic. This is achieved by deriving unique, ephemeral session keys for each communication session, which are not directly tied to the long-term key in a way that allows retrospective decryption. Consequently, even if an attacker gains access to the permanent credentials, past communications remain secure, significantly bolstering privacy and data protection.
- C
Use of TKIP for encryption
Why it fails: The use of Temporal Key Integrity Protocol (TKIP) for encryption is explicitly deprecated and not supported in WPA3, as TKIP was designed as a stopgap measure for WPA to address WEP's weaknesses and has known cryptographic vulnerabilities. TKIP's design includes flaws that make it susceptible to various attacks, including key recovery and message injection, rendering it insecure for modern wireless networks. WPA3 exclusively mandates robust encryption algorithms like GCMP-256 (Galois/Counter Mode Protocol with 256-bit keys) to provide strong confidentiality and integrity.
- D
Simultaneous Authentication of Equals (SAE)
Simultaneous Authentication of Equals (SAE) is a crucial component of WPA3, replacing the Pre-Shared Key (PSK) mechanism used in WPA2-Personal. SAE is a password-based authenticated key exchange protocol that provides robust protection against offline dictionary attacks, even when using weak passwords, by preventing an attacker from capturing the handshake and attempting to guess the password offline. It establishes a strong, shared secret key between the client and access point through a secure exchange, significantly enhancing the security of the initial connection setup.
- E
Support for WEP compatibility
Why it fails: WPA3 explicitly drops support for Wired Equivalent Privacy (WEP) compatibility because WEP is an obsolete and fundamentally insecure encryption protocol with severe cryptographic weaknesses. WEP's vulnerabilities, such as its weak initialization vector (IV) usage and static key management, allow for trivial key recovery and data decryption by attackers using readily available tools. Maintaining compatibility would introduce critical security holes into WPA3 networks, thus its removal is essential for ensuring a secure baseline.