A vendor proposes enabling TKIP “for compatibility” on a brand-new municipal public-safety WLAN. Which encryption decision aligns with current security design practice?
Select an answer to reveal the explanation.
Short Explanation
TKIP was the duct-tape era after WEP—fine history lesson, bad choice for a fresh public-safety build. New designs should land on CCMP or GCMP with AES. Compatibility nostalgia is not a security architecture.
Full Explanation
TKIP is a deprecated interim encryption method and must not be selected as the encryption solution for new WLAN designs. Modern architectures use AES-based CCMP and/or GCMP according to suite and client support. Mixing WEP/TKIP or leaving data unprotected contradicts current WLAN security design objectives. Differentiating deprecated versus current encryption methods is a required CWSP skill.