โ† All CWS Flashcard Decks

CWS WLAN Security Concepts Flashcards

7 cards from real CWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CWS WLAN Security Concepts flashcards as text
  1. What is a PMKID attack and why is it more dangerous than a traditional handshake capture attack?

    Answer: It can be performed without any connected clients by capturing a single EAPOL frame from the AP

    A PMKID attack extracts the PMKID from a single EAPOL frame sent by the AP, enabling offline cracking without needing an active client connection.

  2. In 802.1X authentication, what is the role of the supplicant?

    Answer: The client device requesting network access

    The supplicant is the client device (e.g., laptop or phone) that requests access to the network and provides credentials during 802.1X authentication.

  3. Which countermeasure directly addresses the threat of deauthentication flood attacks?

    Answer: Enabling 802.11w (Management Frame Protection)

    802.11w protects unicast management frames including deauthentication and disassociation frames from being forged by an attacker.

  4. A wireless network uses EAP-PEAP. Which credential type does the inner authentication typically verify?

    Answer: Username and password (MSCHAPv2)

    PEAP typically uses MSCHAPv2 as the inner authentication method, verifying username and password inside a TLS tunnel established by the server certificate.

  5. What is the key difference between an ad-hoc (IBSS) network and an infrastructure (BSS) network from a security perspective?

    Answer: IBSS networks lack a central AP to enforce security policies

    Ad-hoc networks operate peer-to-peer without an AP, making centralized security policy enforcement impossible and increasing risk.

  6. Which protocol is used to securely tunnel EAP authentication between the wireless AP (authenticator) and the RADIUS server?

    Answer: RADIUS over UDP with shared secret

    RADIUS communicates between the AP and authentication server over UDP, protecting the payload with MD5 hashing and a shared secret (though RADSEC/TLS is more secure).

  7. What security risk is introduced when clients auto-connect to remembered SSIDs?

    Answer: Susceptibility to evil twin or karma attacks from rogue APs broadcasting the saved SSID

    When a device probes for known SSIDs or auto-connects to any matching SSID, a rogue AP broadcasting that SSID can intercept the connection.