SSCP Network and Communications Security Practice Question
Which THREE of the following are security features of WPA3 compared to WPA2? (Select THREE)
⚠ Common exam trap
SSCP often tests the confusion between WPA2 and WPA3 features; candidates may incorrectly select TKIP or WEP compatibility because they associate older encryption with broader compatibility, but WPA3 explicitly drops these legacy protocols.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Protected Management Frames (PMF) mandatory
Option B is correct because WPA3 mandates Protected Management Frames (PMF, defined in 802.11w), which cryptographically protect management frames such as deauthentication and disassociation, preventing forgery and denial-of-service attacks that were possible under WPA2 where PMF was optional. Option C is correct because WPA3-Enterprise offers an optional 192-bit security suite aligned with CNSA guidance, using stronger cryptographic algorithms (GCMP-256, HMAC-SHA-384, ECDHE with a 384-bit curve) that WPA2-Enterprise did not provide. Option D is correct because WPA3 replaces the WPA2 Pre-Shared Key handshake with Simultaneous Authentication of Equals (SAE), a Dragonfly-based password-authenticated key exchange that provides forward secrecy and resists offline dictionary attacks against captured handshakes. Option A is incorrect because WPA3 does not support backward compatibility with WEP, a deprecated and broken encryption protocol; WPA3 requires modern ciphers such as CCMP-128 or GCMP-256. Option E is incorrect because TKIP is a legacy, deprecated encryption protocol from WPA/WPA2 and is not used by WPA3, which relies on AES-based CCMP and GCMP instead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Backward compatibility with WEP
Why it's wrong here
WEP compatibility is not a WPA3 security feature; WPA3 removes WEP and TKIP support entirely, requiring CCMP-128 or GCMP-256. The distractor tempts because WPA2 offered an optional WEP/TKIP mixed mode for legacy hardware, so backward compatibility sounds familiar. That legacy support weakened security, which is precisely what WPA3 eliminates.
- ✓
Protected Management Frames (PMF) mandatory
Why this is correct
WPA3 makes Protected Management Frames mandatory, whereas WPA2 left PMF optional. PMF cryptographically protects management frames such as deauthentication and disassociation, preventing forgery and denial-of-service attacks. This mandatory enforcement is a specific WPA3 security improvement over WPA2 that the stem asks you to identify.
- ✓
192-bit security suite for Enterprise mode
Why this is correct
WPA3 adds a 192-bit cryptographic security suite for Enterprise mode, aligned with CNSA guidance. WPA2 Enterprise offered no equivalent mandated 192-bit suite. This stronger Enterprise cipher suite is a distinct WPA3 security enhancement over WPA2, satisfying the stem's requirement for a genuine WPA3 feature.
- ✓
Simultaneous Authentication of Equals (SAE) replaces PSK
Why this is correct
WPA3 replaces the WPA2 pre-shared key handshake with Simultaneous Authentication of Equals, a dragonfly-based password-authenticated key exchange. SAE resists offline dictionary attacks against captured handshakes, which PSK cannot. This replacement is a defining WPA3 security feature the stem requires.
- ✗
Use of TKIP encryption
Why it's wrong here
TKIP is a deprecated WPA cipher that WPA3 removes; WPA3 mandates AES-CCMP and GCMP, so citing TKIP inverts the comparison. It is tempting because TKIP was a WPA2-era option, but the stem asks for WPA3 security features, which include SAE, forward secrecy and protected management frames.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is migrating from WPA2-PSK to WPA3 for its wireless network. Which THREE benefits does WPA3 provide compared to WPA2?
medium- ✓ A.Mandatory use of Protected Management Frames (PMF)
- B.Use of TKIP as the mandatory encryption protocol
- ✓ C.Support for 192-bit security suite in Enterprise mode
- ✓ D.Resistance to offline dictionary attacks through SAE
- E.Backward compatibility with WEP devices
Why A: Option A is correct because WPA3 mandates Protected Management Frames (PMF, defined in 802.11w), which cryptographically protects management frames such as deauthentication and disassociation, preventing spoofing and denial-of-service attacks that remain possible under WPA2 where PMF is optional. Option C is correct because WPA3-Enterprise offers an optional 192-bit security mode based on CNSA Suite algorithms (GCMP-256, HMAC-SHA-384, ECDHE and ECDSA with 384-bit curves), providing stronger cryptographic protection than the standard WPA2-Enterprise 128-bit suite. Option D is correct because WPA3 replaces the WPA2-PSK 4-way handshake with Simultaneous Authentication of Equals (SAE), a Dragonfly-based password-authenticated key exchange that resists offline dictionary attacks by requiring live interaction with the AP for each guess. Option B is incorrect because TKIP is a deprecated, legacy encryption protocol; WPA3 requires CCMP-128 at minimum and does not mandate TKIP. Option E is incorrect because WPA3 does not provide backward compatibility with WEP devices, which use the obsolete RC4-based WEP cipher and cannot negotiate WPA3 security.
Variation 2. A company is migrating from WPA2 to WPA3 for wireless security. Which THREE features does WPA3 introduce? (Select three)
medium- ✓ A.192-bit security suite for Enterprise networks
- B.Wi-Fi Protected Setup (WPS)
- ✓ C.Simultaneous Authentication of Equals (SAE)
- ✓ D.Protected Management Frames (PMF) mandatory
- E.CCMP encryption as mandatory
Why A: WPA3 introduces the 192-bit security suite for Enterprise networks (option A), which is based on CNSA Suite algorithms and provides stronger cryptographic protection for government, defense, and high-security enterprise environments. Simultaneous Authentication of Equals (SAE) (option C) is the new WPA3-Personal handshake that replaces WPA2's PSK method, providing forward secrecy and resistance to offline dictionary attacks. Protected Management Frames (PMF) mandatory (option D) is correct because WPA3 requires PMF (802.11w) to protect management frames from forging and eavesdropping attacks, whereas it was optional in WPA2. Wi-Fi Protected Setup (WPS) (option B) is not a WPA3-introduced feature; it predates WPA3 and is actually discouraged due to security weaknesses. CCMP encryption as mandatory (option E) is incorrect because CCMP is the WPA2 mandatory cipher, while WPA3-Personal still uses CCMP-128 but also introduces GCMP-256 in the 192-bit suite, so CCMP being 'mandatory' is not a new WPA3 feature.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.