City IT is retiring WPA2-Personal on the parks-crew SSID because offline dictionary attacks against a shared passphrase keep succeeding in audits. Which WPA3-Personal AKM mechanism should replace that password-based design?
Select an answer to reveal the explanation.
Short Explanation
WPA2-Personal’s shared PSK is like one master key hanging on a hook—steal the hash, grind it offline, and you’re in. SAE is a password handshake that doesn’t hand attackers that same offline gift. Same idea of a passphrase, much better ceremony.
Full Explanation
WPA3-Personal uses SAE rather than the WPA2-Personal PSK AKM that is vulnerable to offline dictionary attacks against captured handshakes. Shortening a classic PSK worsens security. WEP and MAC allow-lists are deprecated or weak substitutes and do not meet WPA3-Personal AKM expectations on CWSP.