Security Fundamentals // Lesson 09

Wireless Security Protocols.

Compare WPA, WPA2 and WPA3, personal and enterprise authentication, and the weaknesses of legacy wireless protection.

WPAWPA2WPA3PSK802.1X
01 // Mental model

Start with the big picture.

A legacy transition from WEP, commonly associated with TKIP; it should not be chosen for new secure deployments.

CCNA focus: The SSID is not a security boundary by itself. Select modern encryption and authentication, protect management access and segment wireless clients according to risk.
02 // Building blocks

Know what each part does.

01

WPA

A legacy transition from WEP, commonly associated with TKIP; it should not be chosen for new secure deployments.

02

WPA2

Uses the IEEE 802.11i security model and commonly AES-CCMP; still widely encountered.

03

WPA3

Modernises personal authentication with SAE and strengthens protections, subject to client and infrastructure support.

04

Personal vs enterprise

Personal uses a shared credential; enterprise uses 802.1X/EAP with per-user or per-device authentication.

03 // Compare and recognise

Read the clues.

ItemWhat to remember
WEPBroken legacy protection; do not use.
TKIPLegacy mechanism associated with WPA; avoid.
AES-CCMPCommon WPA2 data-confidentiality and integrity mechanism.
SAEWPA3-Personal password-authenticated key exchange resistant to offline guessing in the way PSK handshakes are not.
04 // Protocol choice

Protocol choice.

Home / small office:
  Prefer WPA3-Personal where every client supports it
  Otherwise use WPA2-AES with a long unique passphrase

Enterprise:
  Use WPA2-Enterprise or WPA3-Enterprise
  Authenticate through 802.1X/EAP and RADIUS
  Validate server certificates on clients

Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.

05 // Exam and troubleshooting

Turn facts into a method.

  • Broken legacy protection; do not use.
  • Legacy mechanism associated with WPA; avoid.
  • Common WPA2 data-confidentiality and integrity mechanism.
  • WPA3-Personal password-authenticated key exchange resistant to offline guessing in the way PSK handshakes are not.
Exam checkpoint: The SSID is not a security boundary by itself. Select modern encryption and authentication, protect management access and segment wireless clients according to risk.
06 // Check yourself

Wireless Security Protocols quiz.

1. Which protocol is broken and should not be used?

2. Which algorithm is commonly associated with WPA2?

3. What does WPA3-Personal use instead of the classic PSK handshake?

4. What does enterprise wireless commonly use for individual identity?

5. Is hiding the SSID a substitute for encryption?

Score: 0 / 5