Protected Access & Authentication Methods

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/34

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:23 PM on 7/18/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

35 Terms

1
New cards

Why do wireless LANs require careful configuration to make the connection and transmissions secure?

no way to prevent anything within range from listening to the signals

2
New cards

What could unencrypted wireless traffic allow?

interception of data or unauthorized use of the network

3
New cards

What was the first version of WPA designed to fix?

critical vulnerabilities in the earlier WEP standard

4
New cards

What cipher does version 1 of WPA use to encrypt traffic?

RC4 symmetric cipher

5
New cards

What mechanism did WPA version 1 add to mitigate attacks against WEP?

Temporal Key Integrity Protocol (TKIP)

6
New cards

Why has TKIP been deprecated?

found to have its own share of vulnerabilities

7
New cards

What replaced TKIP?

Advanced Encryption Standard (AES)

8
New cards

How does AES encrypt data?

symmetric keys and block ciphers, dividing data into 128-bit blocks and encrypting each block independently

9
New cards

Which Wi-Fi security versions use AES?

WPA2 and WPA3

10
New cards

Why are WEP and the original WPA not considered secure enough for continued use?

WPA with TKIP is vulnerable to replay attacks that aim to recover the encryption key

11
New cards

What does WPA2 use instead of RC4 and TKIP?

AES deployed within CCMP

12
New cards

What does CCMP provide?

authenticated encryption designed to make replay attacks harder

13
New cards

Which WPA2 mode is better to select?

WPA2-AES

14
New cards

What WPA2 personal authentication mechanism is vulnerable to manipulations that allow recovery of the key?

4-way handshake with a preshared key (PSK)

15
New cards

What does WPA3 replace WPA2-PSK with?

WPA3-SAE

16
New cards

What updated cryptographic protocol does WPA3 use instead of AES CCMP?

AES Galois Counter Mode Protocol (GCMP)

17
New cards

What protection does WPA3 require for management frames?

encryption

18
New cards

What attacks does encrypting management frames help protect against?

key recovery attacks and DoS attacks that force stations to disconnect

19
New cards

What does WPA3 do for an open Wi-Fi network with no passphrase?

encrypts the traffic so any station can still join, but traffic is protected against sniffing

20
New cards
What are the three types of Wi-Fi authentication?
open, personal, and enterprise
21
New cards
What are the two methods within the personal authentication category?
WPA2 pre-shared key (PSK) authentication and WPA3 Simultaneous Authentication of Equals
22
New cards
What does WPA2 pre-shared key authentication use to generate the key that encrypts communications?
a passphrase
23
New cards
Why is WPA2-PSK also referred to as group authentication?
a group of users shares the same passphrase
24
New cards
When an access point is set to WPA2-PSK mode, how long can the configured passphrase be?
8 to 63 characters
25
New cards
What is the passphrase converted into in WPA2-PSK?
a hash value referred to as the pairwise master key (PMK)
26
New cards
What must be configured on each station that joins the network in WPA2-PSK?
the same secret
27
New cards
What is the PMK used for in WPA2?
as part of WPA2's 4-way handshake to derive various session keys
28
New cards
What vulnerability affects all types of PSK authentication?
attacks that attempt to recover the passphrase
29
New cards
How long must the passphrase be to try to mitigate risks from cracking?
at least 14 characters long
30
New cards
What replaces the PSK mechanism in WPA3 personal mode?
the simultaneous authentication of equals (SAE) protocol
31
New cards
What does SAE use to authenticate?
a 128-bit key and perfect forward secrecy
32
New cards
What does perfect forward secrecy generate?
a new key for every transmission
33
New cards
Why does perfect forward secrecy make the handshake much more secure from hackers?
if the hacker intercepts and cracks one of the messages, they still won't be able to crack the keys
34
New cards
What labels might access point configuration interfaces use instead of WPA2-PSK and WPA3-Personal?
WPA2-Personal and WPA3-SAE
35
New cards
What WPA3 configuration choice supports legacy WPA2 clients but weakens security?
WPA3-Personal Transition mode