โ† All CWS Flashcard Decks

CWS WLAN Security Concepts Flashcards

7 cards from real CWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CWS WLAN Security Concepts flashcards as text
  1. Which WLAN security protocol was deprecated due to its use of RC4 and a 24-bit initialization vector?

    Answer: WEP (Wired Equivalent Privacy)

    WEP is critically flawed because its 24-bit IV is too short, leading to IV reuse, and RC4 is vulnerable to statistical attacks that can recover the key in minutes.

  2. An organization wants to allow guest Wi-Fi access without exposing internal resources. Which architecture best achieves this?

    Answer: Separate guest SSID mapped to an isolated VLAN with firewall rules

    A separate guest SSID on an isolated VLAN with firewall policies ensures guests have internet access without any path to internal network resources.

  3. What does a wireless IDS/IPS do when it detects a rogue AP on the network?

    Answer: It can alert administrators and/or use over-the-air deauthentication to contain the rogue AP

    A WIDS/WIPS can alert staff and, through automated containment, send spoofed deauth frames to disconnect clients from the rogue AP.

  4. In the context of WLAN security, what is a 'disassociation attack'?

    Answer: Sending forged disassociation frames to disconnect clients from the AP

    A disassociation attack sends spoofed 802.11 disassociation frames from the AP's MAC address, forcing clients to disconnect and potentially reconnect to a rogue AP.

  5. Which key hierarchy element is unique to each client-AP session and is used to derive the actual encryption and integrity keys?

    Answer: PTK (Pairwise Transient Key)

    The PTK is derived from the PMK during the four-way handshake and is unique per session; it contains the TK, MIC keys, and EAPOL keys used for the session.

  6. Why is hiding an SSID (not broadcasting it in beacon frames) considered a weak security control?

    Answer: Hidden SSIDs still appear in probe requests and responses, making them easily discoverable with passive scanning tools

    Clients actively probe for hidden SSIDs by name, and those probe requests are visible to anyone performing passive wireless scanning, revealing the hidden SSID.

  7. A CWS candidate reviews a WLAN deployment using WPA2-Enterprise with PEAP-MSCHAPv2. What critical client-side configuration is required to prevent credential theft?

    Answer: Validating the RADIUS server's certificate and pinning the CA

    Without validating the RADIUS server certificate on the client, an attacker running a rogue RADIUS server can intercept MSCHAPv2 credentials via a man-in-the-middle attack.