ExamOpsPractice free

Cisco Certified Network Associate (CCNA) 200-301 · Free study guide

Objective 5.9 — Compare WPA generations

Wi-Fi security combines link protection, authentication, key handling, client capabilities, and operational policy. WPA, WPA2, and WPA3 represent generations of protection, but a version label alone does not state whether the WLAN uses a shared personal credential or enterprise identity services.

Place the generations in context

Original WPA was a transitional improvement for older hardware and should be viewed as legacy. WPA2 made stronger AES-based protection the normal target and has broad client support. WPA3 adds modern protections, including a stronger personal-mode password exchange and improved resilience against some offline guessing workflows. The exact supported feature set still depends on the client, access point, and configuration.

Migration modes may allow older and newer clients during a transition, but they preserve some legacy exposure and complicate troubleshooting. Inventory clients before enforcing a new minimum, then define an end date for compatibility rather than leaving a mixed mode indefinitely.

Separate personal and enterprise identity

Personal mode uses a shared secret for the WLAN. Every authorized device that knows it can generally authenticate, and removing one user may require changing the secret everywhere. Use a long, unique credential and protect its distribution. A strong shared secret encrypts the wireless link but does not provide individual accountability.

Enterprise mode integrates an authentication framework and typically gives users or devices individual credentials. Its security depends on correct server validation, identity lifecycle, and backend policy. A client that accepts any authentication server can be tricked even if the advertised WLAN name looks right.

Worked scenario

A small office uses WPA2 personal mode with AES, but the same short pre-shared key is printed in a public meeting room and never changed after contractors leave. The encryption generation is not the main weakness; credential exposure and lifecycle are. Replace the shared secret, limit who receives it, separate guest access, and consider individual enterprise identities if operationally appropriate. WPA3-capable clients can be migrated through a planned compatibility test.

Avoid false assurances

An SSID is a network name, not an identity proof. Hiding it is not a meaningful replacement for authentication. Wireless encryption protects the radio link to the infrastructure, not necessarily the application beyond it. HTTPS, authorization, segmentation, patching, monitoring, and safe DNS remain important.

Verification evidence

Check the security mode, allowed cipher or protection suite, personal or enterprise authentication, management-frame options where supported, and client compatibility. Test a valid client, an invalid credential, roaming if required, and access policy after association. Inspect logs without exposing the shared secret or user credentials.

Common traps

Readiness checklist

Practice and apply this objective

A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.

Start practicing free