WPA2

The Wi-Fi security certification based on IEEE 802.11i, with mandatory AES-based CCMP encryption, offered as Personal (shared passphrase) or Enterprise (IEEE 802.1X).

WPA2 is the Wi-Fi Alliance certification, introduced in 2004, for the full security design of the IEEE 802.11i amendment. Its central change from WPA was mandatory CCMP, which uses AES in place of the RC4 cipher behind TKIP and WEP. WPA2-Personal derives its keys from a passphrase shared by every user. WPA2-Enterprise authenticates each user or device through IEEE 802.1X, with an EAP method such as EAP-TLS and an authentication server. In both modes a four-way handshake between client and access point confirms the keys and derives fresh ones for the session.

The commonly taught weakness sits in Personal mode. An attacker who captures the four-way handshake can guess passphrases offline, at their own speed, without touching the network again, so a short or common passphrase fails quickly. Every user shares one secret, so removing one user means changing it for all. Management frames are unprotected unless an optional protection is enabled. WPA3 answers the offline guessing with SAE and the management frames with required protection, though a Personal passphrase is still shared.

Exam relevance: a scenario is likely to ask which wireless configuration fits a situation. Candidates are expected to choose WPA2-Enterprise where individual accountability or revocation matters, to explain why a weak Personal passphrase is exposed to offline guessing, and to see WPA2 with CCMP as a minimum rather than the current best.