CCMP (Counter Mode CBC-MAC Protocol)
The AES-based data protection protocol from IEEE 802.11i that WPA2 requires: counter mode encrypts each frame and CBC-MAC checks its integrity, replacing the RC4-based TKIP.
CCMP, in full Counter Mode with Cipher Block Chaining Message Authentication Code Protocol, is the wireless data confidentiality and integrity protocol defined by the IEEE 802.11i amendment and now part of the IEEE 802.11 standard. It runs the AES block cipher in CCM mode, with a 128-bit key in its standard form. Counter mode supplies the encryption, and CBC-MAC produces a message integrity code over the frame, so tampering is detected. A packet number carried in each frame lets the receiver reject replayed frames. NIST SP 800-97 notes that support for CCMP is mandatory for any device claiming robust security network compliance.
CCMP is the encryption behind WPA2, and support for it is mandatory there. It replaced the Temporal Key Integrity Protocol (TKIP), the stopgap used by WPA, which kept the RC4 cipher of Wired Equivalent Privacy (WEP) so that older hardware could run it. WPA3 still uses CCMP in its common modes and adds a stronger GCMP-based suite for its optional higher-security enterprise mode. CCMP protects frames on the air, not the passphrase: a weak WPA2 passphrase can still be guessed.
Exam relevance: a scenario is likely to name a cipher or protocol and ask which Wi-Fi generation it belongs to. Candidates are expected to pair RC4 with WEP and TKIP, and AES with CCMP and WPA2.