โ† All CEH Flashcard Decks

Wireless Network Hacking Flashcards

7 cards from real CEH practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Wireless Network Hacking flashcards as text
  1. The KRACK (Key Reinstallation Attack) vulnerability affects which wireless security protocol?

    Answer: WPA2

    KRACK exploits a flaw in the WPA2 four-way handshake, allowing an attacker to force nonce reuse by replaying handshake messages, potentially decrypting encrypted traffic.

  2. An attacker uses airodump-ng and discovers an access point with ESSID . What does this indicate?

    Answer: The AP has SSID broadcast disabled (hidden SSID)

    When an access point's SSID broadcast is disabled, tools like airodump-ng display the ESSID as empty or with length 0; the SSID can still be discovered through probe requests from clients.

  3. Which Bluetooth attack allows an attacker to send unsolicited messages or files to a discoverable Bluetooth device without pairing?

    Answer: Bluejacking

    Bluejacking involves sending unsolicited messages (like vCards or text) to a discoverable Bluetooth device without requiring authentication or pairing.

  4. What technique does an attacker use to bypass MAC address filtering on a wireless network?

    Answer: Sniff the WLAN to capture a legitimate client's MAC address and spoof it

    MAC filtering is easily bypassed by passively monitoring the wireless network to identify an allowed MAC address, then spoofing that MAC on the attacker's wireless adapter.

  5. Wardriving is defined as:

    Answer: Driving around in a vehicle with a Wi-Fi-enabled device to discover and map wireless networks

    Wardriving involves traveling through an area while using wireless scanning tools to discover, log, and sometimes map wireless networks, often combined with GPS.

  6. Which tool is commonly used as a rogue access point and wireless man-in-the-middle platform, often called the 'Hacker's Swiss Army Knife for Wi-Fi'?

    Answer: Wi-Fi Pineapple

    The Wi-Fi Pineapple is a hardware platform designed for wireless auditing and man-in-the-middle attacks, capable of auto-associating clients and intercepting their traffic.

  7. In 802.11 terminology, what is a 'probe request' and how can attackers exploit it?

    Answer: A management frame sent by clients searching for known networks; exploited to discover hidden SSIDs and track device movement

    Probe requests are sent by client devices to actively search for previously connected networks; attackers use them to discover hidden SSIDs and track users based on their device's preferred network list.