220-1102 Question 395
Single answerWPA3A small accounting office upgrades its wireless router to a model that supports WPA3. After the change, several newer laptops connect successfully, but a few older company-owned devices can no longer join the secure Wi-Fi network. The office wants to keep the strongest practical security while allowing those older devices to connect during a planned hardware refresh next quarter. Which configuration should the technician recommend?
- A
Enable WPA3-Personal only on the SSID and manually lower the signal strength for older devices
- B
Change the wireless network to WPA2-Personal with TKIP so older devices can authenticate
- C
Configure WPA2/WPA3 transitional mode on the SSID so compatible devices use WPA3 while legacy devices use WPA2
- D
Disable encryption temporarily and rely on MAC filtering until all devices are replaced
Show answer and explanation
Correct answer: C
Explanation
The best answer is to configure WPA2/WPA3 transitional mode. In a real-world migration, this is the practical way to preserve compatibility while still allowing newer devices to benefit from WPA3-Personal security improvements, including protection against offline password-guessing attacks through SAE (Simultaneous Authentication of Equals). A technician should avoid falling back to weak legacy settings such as TKIP or, worse, disabling encryption. Current Wi-Fi security best practices from the Wi-Fi Alliance and vendor documentation generally recommend WPA3 where supported, transitional mode during phased upgrades, and AES-based protection rather than deprecated legacy protocols.
- A. Incorrect.
This is incorrect. WPA3-Personal only mode provides strong security, but it will continue to block devices that do not support WPA3. Lowering signal strength has nothing to do with authentication or encryption compatibility and would not solve the connection issue.
- B. Incorrect.
This is incorrect. While WPA2-Personal may allow older devices to connect, using TKIP is outdated and not a best practice. TKIP is weaker than AES/CCMP and should not be selected for a modern business WLAN unless there is a very specific legacy requirement, which would still reduce security more than necessary.
- C. Correct.
This is correct. WPA2/WPA3 transitional mode is designed for environments migrating to WPA3. It allows WPA3-capable clients to connect using WPA3-Personal while older devices that only support WPA2 can still authenticate using WPA2. This maintains stronger security for supported devices without unnecessarily excluding legacy systems during a transition period.
- D. Incorrect.
This is incorrect. Disabling encryption creates a major security risk, especially in an accounting office handling sensitive financial data. MAC filtering is not a replacement for encryption because MAC addresses can be observed and spoofed. This option weakens security significantly and does not align with wireless security best practices.