โ† All CEH Flashcard Decks

Wireless Network Hacking Flashcards

7 cards from real CEH practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Wireless Network Hacking flashcards as text
  1. Which fundamental cryptographic weakness in WEP makes it vulnerable to key recovery attacks?

    Answer: Reuse of short 24-bit Initialization Vectors leading to keystream collisions

    WEP uses a 24-bit IV that cycles rapidly in busy networks, causing IV reuse and allowing attackers to recover the RC4 keystream and decrypt traffic.

  2. During a WPA2-Personal attack, an attacker captures the four-way handshake. What is the attacker's next step to crack the passphrase?

    Answer: Perform a dictionary or brute-force attack against the captured EAPOL handshake offline

    The captured four-way handshake contains enough information to perform an offline dictionary or brute-force attack to guess the pre-shared key without further interaction with the network.

  3. An attacker sets up an access point with the same SSID as a legitimate network and a stronger signal to lure victims. This attack is called a(n):

    Answer: Rogue AP / Evil Twin attack

    An Evil Twin (or Rogue AP) attack involves creating a fraudulent access point that mimics a legitimate one, causing clients to connect to it instead and enabling traffic interception.

  4. Which tool is most commonly used in CEH scenarios to capture WPA/WPA2 handshakes and crack wireless keys using wordlists?

    Answer: Aircrack-ng

    Aircrack-ng is the standard wireless security auditing suite that includes tools for capturing handshakes (airodump-ng) and cracking them (aircrack-ng) using dictionary attacks.

  5. What is the primary vulnerability exploited by the WPS PIN attack (Reaver)?

    Answer: The WPS PIN is split into two halves that can be brute-forced independently, reducing combinations from 10^8 to ~11,000

    The WPS protocol verifies the two halves of the 8-digit PIN separately, reducing the brute-force search space from 100 million to about 11,000 combinations.

  6. An attacker sends spoofed 802.11 management frames with reason code 7 to disconnect clients from their access point. This technique is known as:

    Answer: Deauthentication (deauth) attack

    A deauthentication attack floods the target with forged deauth management frames, forcing clients to disconnect and re-authenticate, allowing the attacker to capture the WPA handshake.

  7. Which wireless encryption standard introduced CCMP (Counter Mode with CBC-MAC Protocol) based on AES to replace the insecure TKIP?

    Answer: WPA2

    WPA2 (IEEE 802.11i) mandated the use of CCMP/AES as its primary encryption method, providing much stronger security than WPA's TKIP or WEP's RC4.