ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a threat-model review of a new warehouse Wi-Fi network that will connect thousands of battery-powered IoT scanners, you must recommend a measure that protects data in transit, provides resistance to offline dictionary attacks, and reduces the likelihood of users associating with an evil-twin (rogue) access point, while relying only on widely-supported wireless standards. Which design choice BEST meets these requirements?
Disable SSID broadcast and configure MAC address filtering on each wireless access point.
Require WPA3-Personal with Simultaneous Authentication of Equals (SAE) and enable Protected Management Frames (PMF) on all access points.
Deploy WPA2-Personal with a 63-character complex pre-shared key rotated every six months.
Implement a captive portal that forces device users to accept a security policy before receiving network access.
WPA3-Personal replaces the WPA2 pre-shared-key handshake with Simultaneous Authentication of Equals (SAE). SAE performs a password-authenticated key exchange that provides forward secrecy and prevents attackers from capturing a single handshake and then running offline dictionary or brute-force attacks. In addition, WPA3 mandates the 802.11w Protected Management Frames (PMF) feature, which cryptographically protects de-authentication and other management frames frequently spoofed by rogue or "evil twin" access points to force clients to connect to them. Using a long WPA2 pre-shared key improves guessing resistance but still allows offline attacks if an adversary captures the four-way handshake, and it does not protect management frames. Disabling SSID broadcast and enabling MAC filtering offer only obscurity; attackers can easily discover hidden SSIDs and spoof MAC addresses, so they provide little defense against rogue APs or eavesdropping. Captive portals focus on user acknowledgement or web-based authentication and do not add encryption or management-frame protection. Therefore, enabling WPA3-Personal with SAE and PMF is the most effective standards-based solution for the stated goals.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Simultaneous Authentication of Equals (SAE) in WPA3?
Open an interactive chat with Bash
What are Protected Management Frames (PMF) in Wi-Fi networks?
Open an interactive chat with Bash
Why is WPA3-Personal preferred over WPA2-Personal for IoT networks?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .