A parks-and-recreation handheld joins the grounds SSID discovery list but never finishes a secure connection. The device profile is locked to TKIP-only while the AP is AES/CCMP-only per city policy. What is the fault?
Select an answer to reveal the explanation.
Short Explanation
If the radio speaks only TKIP and the AP speaks only AES, they never agree on a cipher. That encryption mismatch blocks the secure connect even when the SSID is visible. Update the client (or profile) to AES/CCMP to match policy.
Full Explanation
Successful secure connection requires compatible pairwise cipher suites between client and AP. A TKIP-only client cannot complete encryption negotiation with an AES/CCMP-only BSS. Passphrase length and SSID visibility do not override cipher mismatch. Technicians align client encryption configuration to the AP’s required modern cipher rather than assuming automatic upgrades.