ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
During a security assessment you capture a four-way handshake from an 802.11g access point running original WPA with a pre-shared key and crack the eight-character passphrase offline. Hardware replacement is delayed, but all existing 802.11g clients support 802.1X. Which configuration change best eliminates this attack vector while preserving client connectivity?
Change the network to 128-bit static WEP and rotate the key every week.
Disable SSID broadcasting and require clients to connect using manually configured network profiles.
Set the TKIP rekey interval to 500 packets to limit the time any single key is valid.
Convert the SSID to WPA-Enterprise by enabling 802.1X/EAP authentication and using a RADIUS server to supply dynamic per-session keys.
WPA-PSK uses a shared passphrase to derive the Pairwise Master Key on every device. Once a four-way handshake is recorded, an attacker can test guessed passphrases offline until the correct key is found. Converting the SSID to WPA configured for 802.1X/EAP (often called WPA-Enterprise) removes the static passphrase. Each client authenticates through a RADIUS server, which supplies a unique Pairwise Master Key for that session; the PSK needed for offline cracking no longer exists. Disabling SSID broadcast, shortening TKIP rekey intervals, or downgrading to WEP leaves the network equally or more vulnerable.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of a four-way handshake in WPA?
Open an interactive chat with Bash
What are 802.1X and EAP in network security?
Open an interactive chat with Bash
Why is WPA-Enterprise considered more secure than WPA-PSK?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Network and Communication Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .