SSCP Network and Communications Security Practice Question
Which wireless security protocol uses the Simultaneous Authentication of Equals (SAE) handshake to replace the Pre-Shared Key (PSK) method and provides stronger protection against offline dictionary attacks?
⚠ Common exam trap
SSCP often tests the difference between WPA2's 4-way handshake (vulnerable to offline dictionary attacks) and WPA3's SAE (resistant) — candidates pick WPA2 thinking it already includes SAE.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA3
WPA3 introduces Simultaneous Authentication of Equals (SAE), a Dragonfly-based handshake that replaces the WPA2 four-way handshake's PSK exchange. SAE provides forward secrecy and resists offline dictionary attacks because each session derives a unique key, so captured handshakes cannot be brute-forced offline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPA2
Why it's wrong here
WPA2 uses the four-way PSK handshake, which is susceptible to offline dictionary attacks on captured frames; SAE arrives only with WPA3. It is tempting because WPA2 is widely deployed and uses AES-CCMP, and would be the right answer if the question asked about the strongest pre-WPA3 protocol.
- ✗
WPA
Why it's wrong here
WPA uses TKIP with the older PSK authentication and does not implement SAE, so it remains vulnerable to offline dictionary attacks against captured handshakes. It is tempting because WPA introduced stronger encryption than WEP, and would suit legacy hardware that cannot support WPA2 or WPA3.
- ✓
WPA3
Why this is correct
WPA3 replaces the pre-shared key handshake with Simultaneous Authentication of Equals, a dragonfly-based exchange that resists offline dictionary attacks. This directly satisfies the requirement for a protocol using SAE instead of PSK, unlike WPA2's four-way handshake.
- ✗
WEP
Why it's wrong here
WEP relies on RC4 with static keys and no SAE handshake, so its authentication is trivially broken and offers no protection against offline dictionary attacks. It is tempting as a historical baseline for wireless encryption, and would only be relevant when documenting deprecated protocols in legacy environments.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.