Skip to main content

CWSP-205 Real Exam Questions

Certified Wireless Security Professional

119 questions available · Page 1 of 12

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Multiple choice

Wireless Intrusion Prevention Systems (WIPS) provide what network security services? (Choose
2.

  1. A

    Configuration distribution for autonomous APs

  2. B

    Wireless vulnerability assessment

  3. C

    Application-layer traffic inspection

  4. D

    Analysis and reporting of AP CPU utilization

  5. E

    Policy enforcement and compliance management

Show answer and explanation

Correct answers: B, E

Question 2 Single choice

You are using a protocol analyzer for random checks of activity on the WLAN. In the process, you notice
two different EAP authentication processes. One process (STA1) used seven EAP frames (excluding ACK
frames) before the 4-way handshake and the other (STA2) used 11 EAP frames (excluding ACK frames) before the 4-way handshake.

Which statement explains why the frame exchange from one STA required more frames than the frame exchange from another STA when both authentications were successful? (Choose the single most probable answer given a stable WLAN.)

  1. A

    STA1 and STA2 are using different cipher suites.

  2. B

    STA2 has retransmissions of EAP frames.

  3. C

    STA1 is a reassociation and STA2 is an initial association.

  4. D

    STA1 is a TSN, and STA2 is an RSN.

  5. E

    STA1 and STA2 are using different EAP types.

Show answer and explanation

Correct answer: E

Question 3 Multiple choice

Given: Many corporations configure guest VLANs on their WLAN controllers that allow visitors to have Internet access only. The guest traffic is tunneled to the DMZ to prevent some security risks.

In this deployment, what risks are still associated with implementing the guest VLAN without any advanced traffic monitoring or filtering features enabled? (Choose 2)

  1. A

    Intruders can send spam to the Internet through the guest VLAN.

  2. B

    Peer-to-peer attacks can still be conducted between guest users unless application-layer monitoring and filtering are implemented.

  3. C

    Unauthorized users can perform Internet-based network attacks through the WLAN.

  4. D

    Guest users can reconfigure AP radios servicing the guest VLAN unless unsecure network management protocols (e.g. Telnet, HTTP) are blocked.

  5. E

    Once guest users are associated to the WLAN, they can capture 802.11 frames from the corporate VLANs.

Show answer and explanation

Correct answers: A, C

Question 4 Single choice

Given: An 802.1X/EAP implementation includes an Active Directory domain controller running Windows Server 2012 and an AP from a major vendor. A Linux server is running RADIUS and it queries the domain controller for user credentials. A Windows client is accessing the network.

What device functions as the EAP Supplicant?

  1. A

    Linux server

  2. B

    Windows client

  3. C

    Access point

  4. D

    Windows server

  5. E

    An unlisted switch

  6. F

    An unlisted WLAN controller

Show answer and explanation

Correct answer: B

Question 5 Single choice

Given: You have a Windows laptop computer with an integrated, dual-band, Wi-Fi compliant adapter. Your laptop computer has protocol analyzer software installed that is capable of capturing and decoding
802.11ac data.

What statement best describes the likely ability to capture 802.11ac frames for security testing purposes?

  1. A

    All integrated 802.11ac adapters will work with most protocol analyzers for frame capture, including the Radio Tap Header.

  2. B

    Integrated 802.11ac adapters are not typically compatible with protocol analyzers in Windows laptops.
    It is often best to use a USB adapter or carefully select a laptop with an integrated adapter that will work.

  3. C

    Laptops cannot be used to capture 802.11ac frames because they do not support MU-MIMO.

  4. D

    Only Wireshark can be used to capture 802.11ac frames as no other protocol analyzer has implemented the proper frame decodes.

  5. E

    The only method available to capture 802.11ac frames is to perform a remote capture with a compatible access point.

Show answer and explanation

Correct answer: B

Question 6 Single choice

You perform a protocol capture using Wireshark and a compatible 802.11 adapter in Linux. When viewing the capture, you see an auth req frame and an auth rsp frame. Then you see an assoc req frame and an assoc rsp frame. Shortly after, you see DHCP communications and then ISAKMP protocol packets.

What security solution is represented?

  1. A

    802.1X/EAP-TTLS

  2. B

    Open 802.11 authentication with IPSec

  3. C

    802.1X/PEAPv0/MS-CHAPv2

  4. D

    WPA2-Personal with AES-CCMP

  5. E

    EAP-MD5

Show answer and explanation

Correct answer: B

Question 7 Single choice

In what deployment scenarios would it be desirable to enable peer-to-peer traffic blocking?

  1. A

    In home networks in which file and printer sharing is enabled

  2. B

    At public hot-spots in which many clients use diverse applications

  3. C

    In corporate Voice over Wi-Fi networks with push-to-talk multicast capabilities

  4. D

    In university environments using multicast video training sourced from professor's laptops

Show answer and explanation

Correct answer: B

Question 8 Single choice

When used as part of a WLAN authentication solution, what is the role of LDAP?

  1. A

    A data retrieval protocol used by an authentication service such as RADIUS

  2. B

    An IEEE X.500 standard compliant database that participates in the 802.1X port-based access control process

  3. C

    A SQL compliant authentication service capable of dynamic key generation and distribution

  4. D

    A role-based access control protocol for filtering data to/from authenticated stations.

  5. E

    An Authentication Server (AS) that communicates directly with, and provides authentication for, the Supplicant.

Show answer and explanation

Correct answer: A

Question 9 Single choice

What is a primary criteria for a network to qualify as a Robust Security Network (RSN)?

  1. A

    Token cards must be used for authentication.

  2. B

    Dynamic WEP-104 encryption must be enabled.

  3. C

    WEP may not be used for encryption.

  4. D

    WPA-Personal must be supported for authentication and encryption.

  5. E

    WLAN controllers and APs must not support SSHv1.

Show answer and explanation

Correct answer: C

Question 10 Single choice

You are implementing a wireless LAN that will be used by point-of-sale (PoS) systems in a retail environment. Thirteen PoS computers will be installed.
To what industry requirement should you ensure you adhere?

  1. A

    ISA99

  2. B

    HIPAA

  3. C

    PCI-DSS

  4. D

    Directive 8500.01

Show answer and explanation

Correct answer: C