WorksheetsA+ - 16B - Compare Wireless Security Protocols
Total questions: 2
Worksheet time: 14mins
Wireless LANs require secure configurations due to their susceptibility to interception and unauthorized access. Wi-Fi Protected Access (WPA) addresses vulnerabilities found in the Wired Equivalent Privacy (WEP) standard. WPA2 enhances security using the Advanced Encryption Standard (AES) cipher, while WPA3 further strengthens security with Simultaneous Authentication of Equals (SAE) and updated cryptographic protocols.
Wi-Fi authentication includes open, personal, and enterprise methods. WPA2-PSK authentication uses a passphrase to generate encryption keys, while WPA3-SAE replaces the 4-way handshake for key exchange. Enterprise authentication, such as WPA2-Enterprise or WPA3-Enterprise, uses Extensible Authentication Protocol (EAP) and allows more advanced authentication methods like EAP-TLS, utilizing digital certificates for multifactor authentication.
Enterprise authentication requires an Authentication, Authorization, and Accounting (AAA) server, which can be implemented using protocols like RADIUS, TACACS+, or Kerberos. RADIUS forwards authentication data securely between the access point and server, while TACACS+ is used for administrative access control. Kerberos facilitates single sign-on (SSO) but is typically used in conjunction with RADIUS or TACACS+ for wireless authentication.
Which mechanism does WPA use to mitigate attacks against WEP?
Temporal Key Integrity Protocol (TKIP)
Extensible Authentication Protocol (EAP)
Advanced Encryption Standard (AES)
Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP)
What cipher does WPA2 use to replace RC4 for encryption?
Advanced Encryption Standard (AES)
Temporal Key Integrity Protocol (TKIP
Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP)
Simultaneous Authentication of Equals (SAE)
Which feature does WPA3 introduce to replace the 4-way handshake in WPA2?
Simultaneous Authentication of Equals (SAE)
Counter Mode with Cipher Block Chaining Message Authentication Code Protocol (CCMP)
Advanced Encryption Standard (AES)
Temporal Key Integrity Protocol (TKIP)
What type of authentication does WPA2-PSK use?
Open
Personal
Enterprise
Shared
What protocol does WPA3 use to replace AES CCMP for encryption?
Temporal Key Integrity Protocol (TKIP)
Simultaneous Authentication of Equals (SAE)
AES Galois Counter Mode Protocol (GCMP)
PMK
How long must a passphrase be in WPA2 to mitigate passphrase recovery attacks?
At least 8 characters
At least 10 characters
At least 14 characters
At least 16 characters
What is the primary advantage of using WPA3 over WPA2 in an open Wi-Fi network?
Enhanced encryption
Simultaneous Authentication of Equals (SAE)
Protected management frames
Wi-Fi Enhanced Open
What does EAP stand for in enterprise authentication?
Enhanced Authorization Protocol
Extensible Authentication Protocol
Encrypted Access Protocol
Enterprise Authorization Process
Which authentication method supports multifactor authentication using digital certificates?
WPA2-PSK
WPA3-SAE
WPA2-Enterprise
WPA3-Enterprise
What protocol allows an access point to forward authentication data securely to an AAA server?
RADIUS
TACACS+
Kerberos
EAPoW
What is the main advantage of using TACACS+ for authentication?
Enhanced encryption
Multifactor authentication
Administrative access control
Single sign-on (SSO)
What protocol does WPA3 use to replace AES CCMP for encryption?
TKIP
SAE
AES Galois Counter Mode Protocol (GCMP)
PMK
Which authentication method is typically used for administrative access to routers and switches?
WPA2-PSK
WPA3-SAE
WPA2-Enterprise
TACACS+
What is the primary function of Kerberos in enterprise authentication?
Secure distribution of passphrases
Forwarding authentication data
Single sign-on (SSO)
Enhanced encryption
Which protocol allows a user to authenticate to a domain controller (DC) on Windows networks?
RADIUS
TACACS+
Kerberos
EAPoW
What is the purpose of using digital certificates in EAP-TLS authentication?
To establish a trust relationship
To forward authentication data
To generate encryption keys
To store passphrases securely
Which WPA3 authentication method allows the access point to forward authentication data without allowing other network access?
RADIUS
TACACS+
EAPoW
Kerberos
What mechanism does WPA3 use to protect against key recovery attacks and DoS attacks?
AES Galois Counter Mode Protocol (GCMP)
Simultaneous Authentication of Equals (SAE)
Protected management frames
Wi-Fi Enhanced Open
How does WPA2-Enterprise authentication differ from WPA2-PSK authentication?
It uses a passphrase for authentication.
It requires a digital certificate for authentication.
It supports multifactor authentication.
It does not involve an AAA server.
What advantage does WPA3-SAE offer over WPA2-PSK in terms of passphrase security?
It requires a shorter passphrase.
It mitigates risks from passphrase recovery attacks.
It uses a different encryption algorithm.
It supports open authentication.
How does WPA3-SAE differ from WPA2-PSK in terms of key exchange?
It uses a 4-way handshake.
It uses a pairwise master key (PMK).
It uses the SAE protocol.
It uses the RC4 symmetric cipher.
What is the primary purpose of an AAA server in enterprise authentication?
To store passphrases securely
To generate encryption keys
To authenticate wireless clients
To forward authentication data
How does WPA3-SAE authentication differ from WPA2-PSK authentication?
It uses a different encryption algorithm.
It uses a shorter passphrase.
It replaces the 4-way handshake with SAE.
It does not involve a group of users.
Have you submitted your standup form yet?
Click the link below
Not yet
I have now.
