Given: You must implement 7 APs for a branch office location in your organization. All APs will be autonomous and provide the same two SSIDs (CORP1879 and Guest). Because each AP is managed directly through a web-based interface, what must be changed on every AP before enabling the WLANs to ensure proper staging procedures are followed?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
What type of WLAN attack is prevented with the use of a per-MPDU TKIP sequence counter (TSC)?
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Given: You are using WEP as an encryption solution. You are using VLANs for network segregation. Why can you not establish an RSNA?
-
A
RSNA connections require TKIP or CCMP.
-
B
RSNA connections require BIP and do not support TKIP, CCMP or WEP.
-
C
RSNA connections require CCMP and do not support TKIP or WEP.
-
D
RSNA connections do not work in conjunction with VLANs.
Reveal answer details
Close answer details
Question 4
Multiple choice
In the basic 4-way handshake used in secure 802.11 networks, what is the purpose of the ANonce and SNonce? (Choose 2)
-
A
They are used to pad Message 1 and Message 2 so each frame contains the same number of bytes.
-
B
The IEEE 802.11 standard requires that all encrypted frames contain a nonce to serve as a Message Integrity Check (MIC).
-
C
They are added together and used as the GMK, from which the GTK is derived.
-
D
They are input values used in the derivation of the Pairwise Transient Key.
-
E
They allow the participating STAs to create dynamic keys while avoiding sending unicast encryption keys across the wireless medium.
Reveal answer details
Close answer details
Question 5
Multiple choice
Given: ABC Company is deploying an IEEE 802.11-compliant wireless security solution using 802.1X/EAP authentication. According to company policy, the security solution must prevent an eavesdropper from decrypting data frames traversing a wireless connection. What security characteristics and/or components play a role in preventing data decryption? (Choose 2)
-
A
Multi-factor authentication
-
B
-
C
PLCP Cyclic Redundancy Check (CRC)
-
D
Encrypted Passphrase Protocol (EPP)
-
E
Integrity Check Value (ICV)
-
F
Reveal answer details
Close answer details
Given: You have a Windows laptop computer with an integrated, dual-band, Wi-Fi compliant adapter. Your laptop computer has protocol analyzer software installed that is capable of capturing and decoding 802.11ac data. What statement best describes the likely ability to capture 802.11ac frames for security testing purposes?
-
A
All integrated 802.11ac adapters will work with most protocol analyzers for frame capture, including the Radio Tap Header.
-
B
Integrated 802.11ac adapters are not typically compatible with protocol analyzers in Windows laptops. It is often best to use a USB adapter or carefully select a laptop with an integrated adapter that will work.
-
C
Laptops cannot be used to capture 802.11ac frames because they do not support MU-MIMO.
-
D
Only Wireshark can be used to capture 802.11ac frames as no other protocol analyzer has implemented the proper frame decodes.
-
E
The only method available to capture 802.11ac frames is to perform a remote capture with a compatible access point.
Reveal answer details
Close answer details
Which WIPS function helps identify an attacker using MAC address spoofing?
-
A
-
B
Deauthentication protection
-
C
-
D
Reveal answer details
Close answer details
Question 8
Multiple choice
Given: The Aircrack-ng WLAN software tool can capture and transmit modified 802.11 frames over the wireless network. It comes pre-installed on Kali Linux and some other Linux distributions. What are three uses for such a tool? (Choose 3)
-
A
Transmitting a deauthentication frame to disconnect a user from the AP.
-
B
Auditing the configuration and functionality of a WIPS by simulating common attack sequences
-
C
Probing the RADIUS server and authenticator to expose the RADIUS shared secret
-
D
Cracking the authentication or encryption processes implemented poorly in some WLANs
Reveal answer details
Close answer details
Given: A WLAN protocol analyzer trace reveals the following sequence of frames (excluding the ACK frames): 1. 802.11 Probe Req and 802.11 Probe Rsp 2. 802.11 Auth and then another 802.11 Auth 3. 802.11 Assoc Req and 802.11 Assoc Rsp 4. EAPOL-KEY 5. EAPOL-KEY 6. EAPOL-KEY 7. EAPOL-KEY What security mechanism is being used on the WLAN?
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Question 10
Single choice
A wireless analyst detects a high volume of disassociation frames from one AP MAC address. What is the most probable explanation?
-
A
Rogue AP broadcasting fake disassociation frames
-
B
-
C
TKIP replay protection in action
-
D
Reveal answer details
Close answer details
Question 11
Single choice
What is one advantage of using EAP-TTLS instead of EAP-TLS as an authentication mechanism in an 802.11 WLAN?
-
A
EAP-TTLS sends encrypted supplicant credentials to the authentication server, but EAP-TLS uses unencrypted user credentials.
-
B
EAP-TTLS supports client certificates, but EAP-TLS does not.
-
C
EAP-TTLS does not require an authentication server, but EAP-TLS does.
-
D
EAP-TTLS does not require the use of a certificate for each STA as authentication credentials, but EAP-TLS does.
Reveal answer details
Close answer details
Question 12
Single choice
Given: In a security penetration exercise, a WLAN consultant obtains the WEP key of XYZ Corporation's wireless network. Demonstrating the vulnerabilities of using WEP, the consultant uses a laptop running a software AP in an attempt to hijack the authorized user's connections. XYZ's legacy network is using 802.11n APs with 802.11b, 11g, and 11n client devices. With this setup, how can the consultant cause all of the authorized clients to establish Layer 2 connectivity with the software access point?
-
A
All WLAN clients will reassociate to the consultant's software AP if the consultant's software AP provides the same SSID on any channel with a 10 dB SNR improvement over the authorized AP.
-
B
A higher SSID priority value configured in the Beacon frames of the consultant's software AP will take priority over the SSID in the authorized AP, causing the clients to reassociate.
-
C
When the RF signal between the clients and the authorized AP is temporarily disrupted and the consultant's software AP is using the same SSID on a different channel than the authorized AP, the clients will reassociate to the software AP.
-
D
If the consultant's software AP broadcasts Beacon frames that advertise 802.11g data rates that are faster rates than XYZ's current 802.11b data rates, all WLAN clients will reassociate to the faster AP.
Reveal answer details
Close answer details
Question 13
Single choice
Given: Your company has just completed installation of an IEEE 802.11 WLAN controller with 20 controller-based APs. The CSO has specified PEAPv0/EAP-MSCHAPv2 as the only authorized WLAN authentication mechanism. Since an LDAP-compliant user database was already in use, a RADIUS server was installed and is querying authentication requests to the LDAP server. Where must the X.509 server certificate and private key be installed in this network?
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Question 14
Single choice
Joe's new laptop is experiencing difficulty connecting to ABC Company's 802.11 WLAN using 802.1X/EAP PEAPv0. The company's wireless network administrator assured Joe that his laptop was authorized in the WIPS management console for connectivity to ABC's network before it was given to him. The WIPS termination policy includes alarms for rogue stations, roque APs, DoS attacks and unauthorized roaming. What is a likely reason that Joe cannot connect to the network?
-
A
Joe disabled his laptop's integrated 802.11 radio and is using a personal PC card radio with a different chipset, drivers, and client utilities.
-
B
Joe's integrated 802.11 radio is sending multiple Probe Request frames on each channel.
-
C
An ASLEAP attack has been detected on APs to which Joe's laptop was trying to associate. The WIPS responded by disabling the APs.
-
D
Joe configured his 802.11 radio card to transmit at 100 mW to increase his SNR. The WIPS is detecting this much output power as a DoS attack.
Reveal answer details
Close answer details
Question 15
Single choice
Given: ABC Hospital wishes to create a strong security policy as a first step in securing their 802.11 WLAN. Before creating the WLAN security policy, what should you ensure you possess?
-
A
Awareness of the exact vendor devices being installed
-
B
Management support for the process
-
C
End-user training manuals for the policies to be created
-
D
Security policy generation software
Reveal answer details
Close answer details
Question 16
Multiple choice
Given: Many corporations configure guest VLANs on their WLAN controllers that allow visitors to have Internet access only. The guest traffic is tunneled to the DMZ to prevent some security risks. In this deployment, what risks are still associated with implementing the guest VLAN without any advanced traffic monitoring or filtering features enabled? (Choose 2)
-
A
Intruders can send spam to the Internet through the guest VLAN.
-
B
Peer-to-peer attacks can still be conducted between guest users unless application-layer monitoring and filtering are implemented.
-
C
Unauthorized users can perform Internet-based network attacks through the WLAN.
-
D
Guest users can reconfigure AP radios servicing the guest VLAN unless unsecure network management protocols (e.g. Telnet, HTTP) are blocked.
-
E
Once guest users are associated to the WLAN, they can capture 802.11 frames from the corporate VLANs.
Reveal answer details
Close answer details
Question 17
Multiple choice
When TKIP is selected as the pairwise cipher suite, what frame types may be protected with data confidentiality? (Choose 2)
-
A
Robust broadcast management
-
B
Robust unicast management
-
C
-
D
-
E
-
F
Reveal answer details
Close answer details
Question 18
Single choice
After completing the installation of a new overlay WIPS for the purpose of rogue detection and security monitoring at your corporate headquarters, what baseline function MUST be performed in order to identify security threats?
-
A
Authorized PEAP usernames must be added to the WIPS server's user database.
-
B
WLAN devices that are discovered must be classified (rogue, authorized, neighbor, etc.) and a WLAN policy must define how to classify new devices.
-
C
Separate security profiles must be defined for network operation in different regulatory domains
-
D
Upstream and downstream throughput thresholds must be specified to ensure that service-level agreements are being met.
Reveal answer details
Close answer details
Question 19
Single choice
Given: Fred works primarily from home and public wireless hot-spots rather than commuting to the office. He frequently accesses the office network remotely from his Mac laptop using the local 802.11 WLAN. In this remote scenario, what single wireless security practice will provide the greatest security for Fred?
-
A
Use an IPSec VPN for connectivity to the office network
-
B
Use only HTTPS when agreeing to acceptable use terms on public networks
-
C
Use enterprise WIPS on the corporate office network
-
D
Use WIPS sensor software on the laptop to monitor for risks and attacks
-
E
Use 802.1X/PEAPv0 to connect to the corporate office network from public hot-spots
-
F
Use secure protocols, such as FTP, for remote file transfers.
Reveal answer details
Close answer details
Question 20
Single choice
Given: In XYZ's small business, two autonomous 802.11ac APs and 12 client devices are in use with WPA2-Personal. What statement about the WLAN security of this company is true?
-
A
Intruders may obtain the passphrase with an offline dictionary attack and gain network access, but will be unable to decrypt the data traffic of other users.
-
B
A successful attack against all unicast traffic on the network would require a weak passphrase dictionary attack and the capture of the latest 4-Way Handshake for each client.
-
C
An unauthorized wireless client device cannot associate, but can eavesdrop on some data because WPA2-Personal does not encrypt multicast or broadcast traffic.
-
D
An unauthorized WLAN user with a protocol analyzer can decode data frames of authorized users if he captures the BSSID, client MAC address, and a user's 4-Way Handshake.
-
E
Because WPA2-Personal uses Open System authentication followed by a 4-Way Handshake, hijacking attacks are easily performed.
Reveal answer details
Close answer details
Question 21
Single choice
The IEEE 802.11 standard defined Open System authentication as consisting of two auth frames and two assoc frames. In a WPA2-Enterprise network, what process immediately follows the 802.11 association procedure?
-
A
-
B
802.1X/EAP authentication
-
C
-
D
-
E
Passphrase-to-PSK mapping
-
F
RADIUS shared secret lookup
Reveal answer details
Close answer details
Question 22
Single choice
You are using a protocol analyzer for random checks of activity on the WLAN. In the process, you notice two different EAP authentication processes. One process (STA1) used seven EAP frames (excluding ACK frames) before the 4-way handshake and the other (STA2) used 11 EAP frames (excluding ACK frames) before the 4-way handshake. Which statement explains why the frame exchange from one STA required more frames than the frame exchange from another STA when both authentications were successful? (Choose the single most probable answer given a stable WLAN.)
-
A
STA1 and STA2 are using different cipher suites.
-
B
STA2 has retransmissions of EAP frames.
-
C
STA1 is a reassociation and STA2 is an initial association.
-
D
STA1 is a TSN, and STA2 is an RSN.
-
E
STA1 and STA2 are using different EAP types.
Reveal answer details
Close answer details
Question 23
Single choice
Which EAP method supports password authentication without requiring a server-side certificate?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
|