Skip to content
ScopefileGet the app

Technique fileHacking wireless networks

WEP vs WPA vs WPA2 vs WPA3: one generation at a time

WEP is broken, WPA was a stopgap, WPA2 with AES became the long-running standard, and WPA3 is the current one. Each generation is defined by three things: its cipher, how it authenticates, and the flaw it is known for. The table below holds all three, and the wireless networks module covers rogue access points and Bluetooth.

Exam
312-50
Domain
6 · Wireless
Targets
8

Four generations, one table

Cipher, authentication and status for each Wi-Fi security generation
TraitWEPWPAWPA2WPA3
Status (differs)Broken, retire itDeprecatedWidespread, patch itCurrent
Cipher (differs)RC4RC4 with TKIPAES-CCMPAES-CCMP, GCMP in the Enterprise suite
Personal mode (differs)One static shared keyPre-shared keyPre-shared keySAE
Enterprise mode (differs)None802.1X802.1X802.1X
Management frames (differs)UnprotectedUnprotectedProtection optionalProtection required
Known for (differs)Weak, repeating IVsInterim fix, legacyKRACK, patchedDragonblood, patched

Tinted rows marked ≠: at least one of the 4 differs from the others.

SAE is Simultaneous Authentication of Equals, also called the Dragonfly handshake.

How each generation replaced the last

Each step addressed the previous generation's main flaw; the last node is where every network should end up
Each step addressed the previous generation's main flaw; the last node is where every network should end up01WEPRC4, static key02WPATKIP stopgap03WPA2AES-CCMP04WPA3SAE, protectedframesEach step addressed the previous generation's main flaw; the last node is where every network should end up01WEPRC4, static key02WPATKIP stopgap03WPA2AES-CCMP04WPA3SAE, protected frames

Why the changes happened

WEP's problems were in the design, so no patch could save it; the industry needed a replacement that existing hardware could run while new chips caught up. That is the whole story of WPA. WPA2 was the clean break, and it lasted because its cipher held. Its weak spots were elsewhere: the handshake, and passphrases short enough to guess.

WPA3 targets those weak spots. Beyond the new Personal handshake, it gives forward secrecy, so recording traffic today and learning the passphrase later does not unlock the old sessions, and it makes protected management frames mandatory, which blunts forged disconnect messages.

RC4 is a stream cipher and AES a block cipher, both symmetric. If those words are shaky, symmetric vs asymmetric vs hashing lays out what each family does.

Where to spend the time

Wireless is Domain 6, a single module weighted at 5% in EC-Council's blueprint v5.0 (checked Oct 11, 2026). Learn the table first; it is the encryption core of the module. Then move on to rogue access points, evil twins and the Bluetooth terms. Skip the message-by-message internals of each handshake; the blueprint names wireless encryption as a topic and stops there.

Match the generation

Try each target without looking at the table, then use the table to check yourself.

Answered 0/8Hits 0

T-01

Which wireless encryption protocol is known to be highly vulnerable to statistical attacks due to its weak initialization vector?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AWPA3 uses SAE and modern AES-based encryption and is the current Wi-Fi security standard, not one with weak IVs.
  2. BCorrect: deprecated WEP uses RC4 with a short 24-bit initialization vector that repeats, so captured traffic reveals the key through statistical analysis.
  3. C802.1X is a port-based authentication framework, not a wireless encryption protocol with initialization vectors.
  4. DWPA2-Enterprise uses AES-CCMP with per-user 802.1X authentication and does not have WEP's IV weakness, though it should be patched against KRACK.
T-02

Which cipher does WPA2 use for encryption in wireless networks?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: WPA2 uses AES in CCMP mode, which replaced TKIP and RC4; WPA2 is still common, though WPA3 is the current recommendation.
  2. BTriple DES is a deprecated block cipher that has never been part of Wi-Fi security standards.
  3. CBlowfish is a block cipher used in some software, such as bcrypt's design, but not in WPA2.
  4. DRC5 is an older block cipher that is not used by WPA2; WEP and the original WPA used the related but different RC4 stream cipher.
T-03

What wireless security feature was introduced in WPA3 to protect against offline dictionary attacks?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AProtected Management Frames guard against deauthentication and spoofed management frames, not offline password guessing.
  2. BOpportunistic Wireless Encryption encrypts open networks without a password, so it does not address dictionary attacks on passphrases.
  3. CCorrect: SAE, the dragonfly handshake, replaces the WPA2 pre-shared key exchange so captured handshakes cannot be cracked offline.
  4. DAES was already used in WPA2, so it is not the WPA3 feature that stops offline dictionary attacks.
T-04

Which security vulnerability affects WPA2 by allowing an attacker to decrypt traffic without knowing the encryption key?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABEAST targeted CBC mode in SSL 3.0 and TLS 1.0, both now deprecated protocols, and has nothing to do with Wi-Fi encryption.
  2. BCorrect: KRACK forced nonce reuse in the WPA2 four-way handshake to decrypt traffic without the key; vendors patched it from 2017 onward.
  3. CPOODLE exploited padding in SSL 3.0, a deprecated protocol, not the WPA2 wireless handshake.
  4. DHeartbleed was a buffer over-read in the OpenSSL heartbeat extension that leaked server memory, unrelated to WPA2.
T-05

Which wireless encryption protocols are considered secure for protecting 802.11 wireless networks?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ATKIP and WEP are both deprecated and breakable, so neither should protect a modern wireless network.
  2. BOriginal WPA relies on TKIP, which is deprecated, so only half of this pair remains acceptable.
  3. CCorrect: WPA3 is the current standard, and WPA2 with AES-CCMP remains acceptable when patched against KRACK, though WPA3 is preferred.
  4. DWEP and WPA with TKIP are both deprecated and vulnerable to practical attacks.
T-06

A network administrator enabled WPA3 transitional mode for better device compatibility. Which vulnerability remains present in this configuration?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AWPA3 transition mode mixes WPA3 and WPA2 clients; it never falls back to deprecated WEP.
  2. BCorrect: transition mode still accepts WPA2 pre-shared key clients, so captured WPA2 handshakes remain exposed to offline dictionary attacks and downgrades.
  3. CBeacons do not carry session keys, so temporal keys cannot be read directly from them in any WPA mode.
  4. DTransition mode supports Protected Management Frames for capable clients, so management traffic is not uniformly exposed in plaintext.
T-07

A company wants to completely eliminate the risk of shared-PSK exposure across its wireless networks. Which implementation most effectively achieves this requirement?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA long passphrase resists guessing but is still one secret shared by everyone, so a leak exposes the whole network.
  2. BWPA3 Personal with SAE resists offline cracking, but every user still shares the same password.
  3. CCorrect: 802.1X Enterprise gives each user individual credentials, so there is no shared key to leak and access can be revoked per person.
  4. DHidden SSIDs and MAC filtering are easily bypassed and do not change the fact that a shared key is in use.
T-08

An audit of an older warehouse network finds access points set to TKIP, an RC4-based cipher with per-packet key mixing designed to run on hardware originally built for WEP. Which Wi-Fi security generation introduced this cipher as an interim fix?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AWEP is the broken predecessor that TKIP was created to patch; WEP itself used RC4 with static keys and weak initialization vectors.
  2. BCorrect: the original WPA introduced TKIP as a stopgap so existing WEP hardware could get per-packet keys and integrity checks through a firmware update.
  3. CWPA2 made AES-CCMP mandatory; it may still allow TKIP for compatibility, but it did not introduce TKIP as the interim fix.
  4. DWPA3 builds on AES-based encryption and SAE authentication; it does not introduce or depend on TKIP for its protection.

Wi-Fi questions that trip people up

What is the difference between a rogue access point and an evil twin?

A rogue access point is any unauthorized access point connected to your network, often plugged in by an employee. An evil twin imitates a legitimate network's name to lure clients onto the attacker's access point. Wireless intrusion prevention systems (the radio-side cousin of the devices in IDS vs IPS vs firewall) and client policies that pin trusted networks address both.

Does an open network with WPA3 have encryption?

It can. Opportunistic Wireless Encryption, sold as Wi-Fi Enhanced Open, encrypts each client's traffic on a network with no password. It does not authenticate the access point, so it protects against passive listening only.

Where does WPS fit?

Wi-Fi Protected Setup is a convenience feature for joining devices, not a security generation. Its PIN method has a known design weakness, so the standard hardening advice is to turn WPS off.

Sources