A parks department insists CCMP is enabled on their Personal SSID, yet auditors still crack the network after capturing a handshake because the passphrase is “Parks2024!”. What AKM lesson should the security lead draw?
Select an answer to reveal the explanation.
Short Explanation
Fancy deadbolts on a screen door don’t help if everyone knows the spare key under the mat. CCMP can be solid crypto and still lose if the Personal PSK is guessable. Cipher suite ≠ AKM strength.
Full Explanation
CCMP (or other strong pairwise ciphers) protects frames after keys are established, but WPA2-Personal AKM still depends on the shared PSK. A weak passphrase remains vulnerable to offline cracking of captured handshake material. Selecting CCMP does not convert Personal mode into Enterprise identity binding or make weak PSKs irrelevant.