Network Implementation 20% Lesson 11 of 14

Lesson 2.3.3 — Wireless Encryption & Authentication: WPA2/WPA3, PSK vs. Enterprise, Guest Networks

Avatar Of Asad IjazAsad Ijaz ·Sep 19, 2026 ·5 min read
79% through domain
Illustration Of An Open Padlock Transforming Into A Closed, Secured Padlock As It Passes Through A Doorway

Domain 2.0 | Network Implementation — 20% of exam

Learning Objectives

By the end of this lesson, you will be able to:

  • Explain why wireless encryption is essential and compare WPA2 and WPA3
  • Distinguish PSK authentication from Enterprise (802.1X) authentication
  • Explain the purpose of guest networks and captive portals
  • Identify the key security improvements WPA3 introduces over WPA2
  • Recognize common wireless encryption and authentication misconfigurations

Key Terms

TermDefinition
WPA2 (Wi-Fi Protected Access 2)A wireless security standard using AES-CCMP encryption, the long-standing baseline for secure Wi-Fi
WPA3 (Wi-Fi Protected Access 3)The successor to WPA2, adding SAE for stronger key exchange and mandatory management frame protection
PSK (Pre-Shared Key)An authentication method where every device on the network uses the same shared passphrase
Enterprise AuthenticationAn authentication method (802.1X) where each user or device authenticates individually against a RADIUS server with unique credentials
Captive PortalA web page that intercepts a guest’s browser, requiring login or acceptance of terms before granting internet access

Explanation

Why Wireless Encryption Matters

The previous lesson covered how wireless networks are named and structured. None of that structure means much without encryption, though — a wired connection at least requires physical access to a cable or a switch port, but a wireless signal broadcasts into open air, reachable by anyone within range holding an ordinary laptop or phone. Without encryption, every wireless transmission could be captured and read by anyone nearby — a very different threat model from the firewalls and security appliances that guard a wired network’s perimeter, since there’s no perimeter to speak of over the air. Wireless encryption exists specifically to close that gap.

WPA2 and WPA3: Evolving Wireless Security

WPA2 has been the dominant wireless security standard for two decades, using AES-CCMP encryption to protect traffic. It replaced the older, badly broken WEP and original WPA standards, and for most of its life, properly configured WPA2 has been considered solidly secure. Its weak point has always been the human element: WPA2’s four-way handshake, when paired with a short or common passphrase, is vulnerable to offline dictionary and brute-force attacks — an attacker can capture the handshake and then try passwords against it without even being connected to the network.

WPA3 addresses this directly. Its headline improvement is SAE (Simultaneous Authentication of Equals), which replaces WPA2’s four-way handshake with a exchange that resists exactly the offline dictionary attack WPA2 was vulnerable to — even if an attacker captures the entire exchange, they can’t productively guess passwords against it offline. WPA3 also makes Protected Management Frames (PMF) mandatory, encrypting the management traffic between clients and access points that WPA2 left unprotected, closing off certain deauthentication and spoofing attacks that relied on that gap.

Diagram Comparing Wpa2'S Vulnerability To Offline Dictionary Attacks Against Wpa3'S Sae Resistance And Mandatory Management Frame Protection
What Wpa3 Changes Versus Wpa2 — Sae And Mandatory Management Frame Protection

PSK vs. Enterprise Authentication

Beyond the encryption standard itself, there’s a separate and equally important decision: how individual users and devices actually authenticate to the network.

  • PSK (Pre-Shared Key) authentication uses one shared passphrase for every device connecting to the network. It’s simple to set up and is the standard choice for home networks and small offices, but it has a real accountability gap: everyone shares the same credential, so there’s no way to tell which specific device or person a given connection belongs to, and if the key needs to be revoked — an employee leaves, a device is lost — the passphrase has to be changed and redistributed to every legitimate device at once.
  • Enterprise authentication, based on the 802.1X framework, has each individual user or device authenticate with its own unique credentials against a centralized RADIUS server. This gives real per-user accountability (the network knows exactly who or what device is connected) and makes revocation clean — disabling one compromised or departing user’s credentials doesn’t require touching anyone else’s access at all.
Diagram Comparing Psk'S Single Shared Key Across Devices Against Enterprise'S Individual Per-User Radius Authentication
How Psk’S Shared Passphrase Differs From Enterprise’S Per-User Radius Authentication

The tradeoff is complexity and cost: Enterprise authentication requires a RADIUS server and more involved client configuration, which is why PSK remains common for smaller deployments even though Enterprise offers meaningfully better security and accountability at scale.

Guest Networks and Captive Portals

Most organizations need to offer wireless access to visitors without exposing internal network resources to them. A guest network solves this by putting visitor traffic on its own separate SSID — typically mapped to its own isolated VLAN — with no path to internal servers, printers, or other private resources, only outbound internet access.

A captive portal is frequently layered on top of a guest network: instead of connecting straight to the internet, a guest’s first web request is intercepted and redirected to a landing page requiring them to accept terms of use, enter a room number or voucher code, or simply click through an acknowledgment before real internet access is granted. This serves both a legal purpose (documenting acceptance of an acceptable use policy) and a practical one (giving the organization a checkpoint to limit or monitor guest access).

Diagram Showing Guest Vlan Traffic Routed Through A Captive Portal To The Internet Only, Blocked From Reaching The Internal Vlan
How A Guest Network And Captive Portal Keep Visitor Traffic Separated From Internal Resources

Recognition-Level Verification Concepts

A few patterns are worth recognizing on sight:

  • A wireless network where every device uses the identical passphrase to connect is running PSK authentication.
  • A network requiring individual username/password (or certificate) login against a RADIUS server is running Enterprise (802.1X) authentication.
  • A guest redirected to a terms-acceptance page before reaching the internet is going through a captive portal.
  • A wireless client unable to reach internal file servers or printers, while still reaching the internet, on a distinctly named guest SSID, reflects correct guest network isolation, not a fault.

Common Exam Traps

  • WPA3’s core improvement is SAE, not simply “a stronger password requirement.” SAE fundamentally changes the key exchange to resist offline dictionary attacks, regardless of how strong or weak the actual passphrase is.
  • PSK and Enterprise are authentication methods, not encryption standards. Either can technically be paired with WPA2 or WPA3 — don’t conflate “which encryption version” with “how users log in.”
  • PSK has no built-in per-user accountability. Every connected device looks identical from the perspective of the shared key itself; distinguishing users requires other means (like MAC tracking), not the PSK itself.
  • A guest network’s isolation from internal resources is intentional, not a misconfiguration. Guests reaching the internet but nothing else on the internal network is the network working exactly as designed.
  • A captive portal is a checkpoint, not an encryption mechanism. It controls initial access to the network; it doesn’t itself encrypt the guest’s ongoing wireless traffic — that’s still handled by whatever WPA standard the network uses.

Lesson 2.3.3 Practice Quiz — Wireless Encryption & Authentication

17 questions covering WPA2, WPA3, SAE, PSK vs. Enterprise authentication, guest networks, and captive portals.

N10-009 · Domain 2.3
Question 1Plain
What is WPA3's key security improvement over WPA2?
WPA3's headline improvement is SAE, which replaces WPA2's four-way handshake with an exchange resistant to offline dictionary attacks.
Question 2Plain
What encryption does WPA2 use?
WPA2 uses AES-CCMP encryption, having replaced the older, broken WEP standard.
Question 3Plain
In PSK authentication, how many passphrases does the network typically use?
PSK (Pre-Shared Key) uses one shared passphrase for every device connecting to the network.
Question 4Choose Two
Which two statements about WPA3 are correct? (Choose two.)
WPA3 makes PMF mandatory and introduces SAE specifically to resist offline dictionary attacks — it is a meaningful security improvement over WPA2, not a downgrade or a passphrase-only change.
Question 5Choose Two
Which two statements about Enterprise (802.1X) authentication are correct? (Choose two.)
Enterprise authentication's core value is individual credentials per user/device and clean, isolated revocation — the opposite of PSK's shared-passphrase model, and it does require a RADIUS server.
Question 6Choose Two
Which two statements about guest networks are correct? (Choose two.)
Guest networks are deliberately isolated from internal resources and are commonly paired with a captive portal for access control — they use a distinct SSID/VLAN, not the same one as the internal network, and never grant internal server access by design.
Question 7Scenario
A company wants every employee device to authenticate with its own unique credentials, so that a specific device's access can be revoked without changing anyone else's login. Which authentication method fits?
Enterprise authentication's individual credentials per device, verified against a RADIUS server, allow exactly this kind of isolated revocation.
Question 8Scenario
A small home network wants the simplest possible wireless setup — one password that every device in the house uses. Which authentication method fits?
A single shared passphrase for every device is exactly PSK authentication — the simple, standard choice for home networks.
Question 9Scenario
A hotel wants guests to accept terms of service and enter a room number before getting internet access over Wi-Fi. What feature accomplishes this?
A captive portal is exactly this: intercepting a guest's browser to require acceptance or login before granting internet access.
Question 10Scenario
A security team is concerned about offline dictionary attacks against weak wireless passphrases and wants to close that specific vulnerability. What should they deploy?
WPA3's SAE mechanism is specifically designed to resist offline dictionary attacks, directly addressing this concern.
Question 11Scenario
An employee leaves the company, and IT needs to revoke their wireless access. On the current PSK-based network, what is required?
This is exactly PSK's accountability gap: since everyone shares one passphrase, revoking one person's access means changing and redistributing the key to everyone else — a scenario Enterprise authentication avoids entirely.
Question 12Exhibit
Based on this access point configuration, what authentication and encryption combination is in use?
SSID: OfficeWiFi Security Mode: WPA2-PSK Passphrase: [shared, single key for all clients]
"WPA2-PSK" directly indicates WPA2 encryption paired with PSK (shared passphrase) authentication.
Question 13Exhibit
Based on this access point configuration, what authentication and encryption combination is in use?
SSID: CorpSecure Security Mode: WPA3-Enterprise RADIUS Server: 10.0.0.50:1812 Authentication: 802.1X (per-user credentials)
"WPA3-Enterprise" with a listed RADIUS server and 802.1X per-user credentials confirms WPA3 encryption paired with Enterprise authentication.
Question 14Exhibit
Based on this client connection log, what authentication method is this client using?
[WLAN-AUTH] Client requesting association to CorpSecure [WLAN-AUTH] EAP identity request sent [WLAN-AUTH] Client responded with username: jsmith [RADIUS] Authentication request forwarded to 10.0.0.50 [RADIUS] Access-Accept received for jsmith
The EAP identity exchange and RADIUS Access-Accept for a specific username (jsmith) confirm this is Enterprise 802.1X authentication, not a shared PSK.
Question 15Exhibit
Based on this firewall rule for the guest VLAN, what is being enforced?
access-list GUEST-ISOLATION deny ip 192.168.50.0 0.0.0.255 192.168.10.0 0.0.0.255 access-list GUEST-ISOLATION permit ip 192.168.50.0 0.0.0.255 any
The deny rule blocks guest-to-internal traffic specifically, while the permit rule allows guest traffic everywhere else (i.e., out to the internet) — textbook guest network isolation.
Question 16Exhibit
Based on this log, what is happening to the guest's connection?
[GUEST-WIFI] Client aa:bb:cc:dd:ee:ff associated to GuestNetwork [GUEST-WIFI] HTTP request intercepted, redirected to https://portal.example.com/welcome [GUEST-WIFI] Client accepted terms — internet access granted
The HTTP interception and redirect to a welcome/terms page before granting access is exactly how a captive portal operates.
Question 17Exhibit
Comparing these two handshake descriptions, which network is resistant to offline dictionary attacks against a captured handshake?
Network A: WPA2-PSK, 4-way handshake captured — offline password guessing possible Network B: WPA3-PSK, SAE exchange captured — offline password guessing not productive
This directly illustrates WPA3's SAE advantage: even with the exchange captured, offline password guessing isn't productive against it, unlike WPA2's four-way handshake.
📝

Summary

Wireless traffic broadcasts into open air, making encryption essential; WPA2 uses AES-CCMP, while WPA3 adds SAE and mandatory Protected Management Frames for stronger security.

WPA3's SAE specifically resists the offline dictionary attacks that WPA2's four-way handshake was vulnerable to, even against weaker passphrases.

PSK authentication uses one shared passphrase for all devices, offering simplicity but no per-user accountability; Enterprise (802.1X) authentication uses individual credentials against a RADIUS server for better accountability and clean revocation.

Guest networks isolate visitor traffic on a separate SSID and VLAN, restricting access to the internet only, with no path to internal resources.

Captive portals intercept a guest's first web request to require acceptance of terms or login before granting internet access, serving both legal and access-control purposes.

Avatar Of Asad Ijaz

Lead Networking Architect and Editor at NetworkUstad. BS in Computer Networks and Security, CCNP and CCNA certified, with 11+ years of experience in enterprise network design, implementation, and troubleshooting. Writes practical tutorials on routing, IPv4 management, network automation, and security fundamentals.