N10-009 exam dumps

N10-009 practice question 168 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 168

Single answerEncryption: Wi-Fi Protected Access 2 (WPA2), WPA3

A company is replacing its wireless infrastructure in a mixed-device environment. The security team wants the strongest possible protection for employee laptops and phones, including resistance to offline password-guessing attacks. However, several older barcode scanners used in the warehouse only support WPA2-Personal. The network administrator must keep the scanners functional during the transition without forcing all users to remain on the older standard. Which solution best meets these requirements?

  1. A

    Configure a WPA3-Personal SSID for modern devices and a separate WPA2-Personal SSID for legacy scanners

  2. B

    Configure a single open SSID and rely on a captive portal for authentication so all devices can connect

  3. C

    Configure a single WPA2-Personal SSID with a complex passphrase because WPA2 provides the same protection against offline guessing as WPA3

  4. D

    Configure WEP on the warehouse SSID for compatibility and WPA3-Personal on the corporate SSID

Show answer and explanation

Correct answer: A

Explanation

The best answer is to deploy separate SSIDs: one using WPA3-Personal for modern devices and one using WPA2-Personal for legacy devices that cannot support WPA3. WPA3-Personal replaces WPA2-Personal's pre-shared key exchange with SAE, which is intended to mitigate offline dictionary attacks and improve wireless authentication security. In real deployments, organizations often maintain a transitional design to preserve compatibility while improving security where supported. An open network with a captive portal does not provide the same over-the-air encryption as WPA2/WPA3, and WEP is deprecated due to serious vulnerabilities. This aligns with Wi-Fi Alliance guidance on WPA3 adoption and common enterprise best practices for phased wireless migrations.

  • A. Correct.

    Correct. WPA3-Personal uses SAE (Simultaneous Authentication of Equals), which provides stronger protection than WPA2-PSK and is designed to resist offline dictionary attacks against captured handshakes. Running a separate WPA3-Personal SSID for capable devices while maintaining a WPA2-Personal SSID for legacy scanners is a practical migration strategy in mixed environments. This allows the organization to improve security for supported devices without breaking older hardware.

  • B. Incorrect.

    Incorrect. An open SSID with a captive portal does not provide equivalent Wi-Fi link-layer encryption for client traffic. Captive portals are commonly used for guest access, but they do not replace WPA2/WPA3 authentication and encryption for protecting wireless communications on the air. This option weakens security rather than strengthening it.

  • C. Incorrect.

    Incorrect. WPA2-Personal with a strong passphrase is still widely used, but it does not provide the same protection model as WPA3-Personal. WPA2-PSK is vulnerable to offline password-guessing attempts if an attacker captures the four-way handshake. WPA3-Personal's SAE was specifically introduced to improve this weakness. Someone might choose this option because strong passwords are important, but it does not satisfy the requirement for stronger resistance to offline guessing attacks.

  • D. Incorrect.

    Incorrect. WEP is obsolete and insecure and should not be deployed for production compatibility purposes. It has well-known cryptographic weaknesses and does not meet modern security best practices or Network+ expectations. While this might seem like a way to support older devices, it creates an unacceptable security risk.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam