The correct answer is C: AES-128. Cisco's WPA2 documentation describes WPA2 as using AES with CCMP; AES Counter Mode encrypts 128-bit blocks with a 128-bit encryption key. The existing answer of AES-256 confuses PSK material or hexadecimal key-entry length with the actual WPA2 CCMP encryption cipher. WPA2-Personal uses a pre-shared key for authentication/key derivation, but the data-protection mechanism is AES-CCMP, not RC4, TKIP with RC4, or plain RC4. TKIP was associated with WPA and is considered legacy; WEP and RC4-based approaches are not acceptable modern wireless protection. CCNA
200-301 v1.1 Network Access expects the basic security pairing: WPA2 uses AES/CCMP, and WPA3 improves authentication with SAE. Because the option set forces a key-size distinction, Cisco's WPA2 configuration reference supports AES-128. Reference: Cisco WPA2 configuration example describing AES Counter Mode and a 128-bit encryption key.
