Network+ Wireless Security Protocols Flashcards
7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network+ Wireless Security Protocols flashcards as text
Which WPA3 feature replaces the Pre-Shared Key (PSK) handshake to protect against offline dictionary attacks?
Answer: SAE (Simultaneous Authentication of Equals)
WPA3 uses SAE, a Dragonfly-based handshake that provides forward secrecy and resists offline brute-force attacks.
A company deploys WPA2-Enterprise. Which server handles credential authentication for wireless clients?
Answer: RADIUS
WPA2-Enterprise uses a RADIUS server to centrally authenticate wireless clients via EAP.
What is the primary vulnerability exploited by the KRACK (Key Reinstallation Attack) against WPA2?
Answer: The four-way handshake nonce reuse
KRACK forces nonce reuse during the WPA2 four-way handshake, allowing an attacker to decrypt traffic.
Which cipher suite does WPA2 mandate for protecting data confidentiality?
Answer: CCMP/AES
WPA2 requires CCMP with AES-128 for data encryption, replacing the weaker TKIP used in WPA.
An attacker captures the WPA2 four-way handshake and runs an offline password cracking tool. Which preventive measure is MOST effective?
Answer: Using a long, complex passphrase
A strong, complex passphrase makes offline dictionary and brute-force attacks computationally infeasible.
Which wireless security protocol introduced the concept of per-packet key mixing to address WEP's IV weaknesses?
Answer: TKIP
TKIP introduced per-packet key mixing, a message integrity check, and IV sequencing to overcome WEP's weaknesses.
In WPA3-Enterprise mode, what is the minimum encryption strength required?
Answer: 192-bit security suite
WPA3-Enterprise requires a 192-bit security suite aligned with Suite B cryptography for high-security environments.