CWS WLAN Security Concepts Flashcards
7 cards from real CWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CWS WLAN Security Concepts flashcards as text
Which attack exploits the 802.11 four-way handshake by capturing it and then running offline dictionary attacks?
Answer: WPA2-PSK brute force via captured handshake
An attacker can capture the WPA2-PSK four-way handshake and perform offline dictionary or brute-force attacks without staying connected to the network.
What is the primary purpose of 802.11w (Management Frame Protection)?
Answer: Protecting management frames from spoofing and replay attacks
802.11w adds cryptographic protection to unicast and some multicast management frames to prevent deauthentication and disassociation spoofing.
In WPA3-Enterprise, what minimum encryption suite is required compared to WPA2-Enterprise?
Answer: GCMP-128 as the minimum cipher
WPA3-Enterprise requires a minimum of GCMP-128, and the 192-bit mode mandates GCMP-256 for stronger government/enterprise security.
A rogue AP is detected broadcasting the same SSID as the corporate network. What type of attack does this describe?
Answer: Evil twin attack
An evil twin attack involves deploying a rogue AP with the same SSID (and often BSSID spoofed) to lure clients into connecting to the attacker's AP.
Which EAP method uses a server-side certificate and a client-side certificate for mutual authentication?
Answer: EAP-TLS
EAP-TLS requires both the RADIUS server and the client to present valid X.509 certificates, providing strong mutual authentication.
What does SAE (Simultaneous Authentication of Equals) replace in WPA3-Personal?
Answer: The PSK-based four-way handshake authentication exchange
SAE replaces the PSK authentication mechanism used in WPA2-Personal, providing forward secrecy and resistance to offline dictionary attacks.
Which wireless security mechanism prevents a compromised session key from exposing past or future sessions?
Answer: Perfect Forward Secrecy (PFS)
Perfect Forward Secrecy ensures that each session uses a unique key, so compromising one session key does not expose other sessions.