nerdexam
EC-Council

112-51 · Question #48

In the context of wireless security, which of the following are benefits of using WPA3? (Select two)

The correct answer is A. Protection against brute-force attacks C. Improved data encryption. WPA3 introduces Simultaneous Authentication of Equals (SAE), which replaces the older Pre-Shared Key handshake and makes offline dictionary and brute-force attacks computationally impractical (A). It also mandates 192-bit encryption (in WPA3-Enterprise) and stronger GCMP-256 ciph

Network Security Controls

Question

In the context of wireless security, which of the following are benefits of using WPA3? (Select two)

Options

  • AProtection against brute-force attacks
  • BElimination of the need for passwords
  • CImproved data encryption
  • DResistance to de-authentication attacks

How the community answered

(27 responses)
  • A
    85% (23)
  • B
    11% (3)
  • D
    4% (1)

Explanation

WPA3 introduces Simultaneous Authentication of Equals (SAE), which replaces the older Pre-Shared Key handshake and makes offline dictionary and brute-force attacks computationally impractical (A). It also mandates 192-bit encryption (in WPA3-Enterprise) and stronger GCMP-256 ciphers, significantly improving data confidentiality over WPA2's CCMP-128 (C).

Why the distractors are wrong:

  • B is incorrect - WPA3 still uses passwords; it just protects them better through SAE's zero-knowledge proof mechanism.
  • D is a common trap: de-authentication attacks (used in Evil Twin and WPA2 KRACK-style scenarios) are partially addressed by Management Frame Protection (MFP/802.11w), which is required by WPA3 - but this benefit is typically attributed to 802.11w/PMF rather than WPA3 itself, and it's not among WPA3's primary headline features for exam purposes.

Memory tip: Think "WPA3 = SAE + Stronger Encryption." SAE → blocks brute force (A), Stronger = better encryption (C). If a choice sounds like WPA3 removes passwords or solves every wireless attack, it's too good to be true.

Topics

#WPA3#Wireless encryption#Brute-force protection#Authentication

Community Discussion

No community discussion yet for this question.

Full 112-51 Practice