HPE6-A78 · Question #86
You have configured a WLAN to use Enterprise security with the WPA3 version. How does the WLAN handle encryption?
The correct answer is D. Traffic is encrypted with AES and keys derived from a unique PMK per client. WPA3-Enterprise is a security protocol introduced to enhance the security of wireless networks, particularly in enterprise environments. It builds on the foundation of WPA2 but introduces stronger encryption and key management practices. In WPA3-Enterprise, authentication is…
Question
You have configured a WLAN to use Enterprise security with the WPA3 version. How does the WLAN handle encryption?
Options
- ATraffic is encrypted with TKIP and keys derived from a PMK shared by all clients on the WLAN.
- BTraffic is encrypted with TKIP and keys derived from a unique PMK per client.
- CTraffic is encrypted with AES and keys derived from a PMK shared by all clients on the WLAN.
- DTraffic is encrypted with AES and keys derived from a unique PMK per client.
How the community answered
(19 responses)- B5% (1)
- C5% (1)
- D89% (17)
Explanation
WPA3-Enterprise is a security protocol introduced to enhance the security of wireless networks, particularly in enterprise environments. It builds on the foundation of WPA2 but introduces stronger encryption and key management practices. In WPA3-Enterprise, authentication is typically performed using 802.1X, and encryption is handled using the Advanced Encryption Standard (AES). WPA3-Enterprise Encryption: WPA3-Enterprise uses AES with the Galois/Counter Mode Protocol (GCMP) or Cipher Block Chaining Message Authentication Code Protocol (CCMP), both of which are AES-based encryption methods. WPA3 does not use TKIP (Temporal Key Integrity Protocol), which is a legacy encryption method used in WPA and early WPA2 deployments and is considered insecure. Pairwise Master Key (PMK): In WPA3- Enterprise, the PMK is derived during the 802.1X authentication process (e.g., via EAP-TLS or EAP-TTLS). Each client authenticates individually with the authentication server (e.g., ClearPass), resulting in a unique PMK for each client. This PMK is then used to derive session keys (Pairwise Transient Keys, PTKs) for encrypting the client's traffic, ensuring that each client's traffic is encrypted with unique keys.
Topics
Community Discussion
No community discussion yet for this question.