Courseiva

SSCP Network and Communications Security Practice Question

Which wireless security protocol uses the Simultaneous Authentication of Equals (SAE) handshake to replace the Pre-Shared Key (PSK) method and provides stronger protection against offline dictionary attacks?

⚠ Common exam trap

SSCP often tests the difference between WPA2's 4-way handshake (vulnerable to offline dictionary attacks) and WPA3's SAE (resistant) — candidates pick WPA2 thinking it already includes SAE.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA3

WPA3 introduces Simultaneous Authentication of Equals (SAE), a Dragonfly-based handshake that replaces the WPA2 four-way handshake's PSK exchange. SAE provides forward secrecy and resists offline dictionary attacks because each session derives a unique key, so captured handshakes cannot be brute-forced offline.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPA2

    Why it's wrong here

    WPA2 uses the four-way PSK handshake, which is susceptible to offline dictionary attacks on captured frames; SAE arrives only with WPA3. It is tempting because WPA2 is widely deployed and uses AES-CCMP, and would be the right answer if the question asked about the strongest pre-WPA3 protocol.

  • ✗

    WPA

    Why it's wrong here

    WPA uses TKIP with the older PSK authentication and does not implement SAE, so it remains vulnerable to offline dictionary attacks against captured handshakes. It is tempting because WPA introduced stronger encryption than WEP, and would suit legacy hardware that cannot support WPA2 or WPA3.

  • ✓

    WPA3

    Why this is correct

    WPA3 replaces the pre-shared key handshake with Simultaneous Authentication of Equals, a dragonfly-based exchange that resists offline dictionary attacks. This directly satisfies the requirement for a protocol using SAE instead of PSK, unlike WPA2's four-way handshake.

  • ✗

    WEP

    Why it's wrong here

    WEP relies on RC4 with static keys and no SAE handshake, so its authentication is trivially broken and offers no protection against offline dictionary attacks. It is tempting as a historical baseline for wireless encryption, and would only be relevant when documenting deprecated protocols in legacy environments.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.