Skip to main content

CWSP-206 Real Exam Questions

CWSP Certified Wireless Security Professional

60 questions available · Page 1 of 6

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

You perform a protocol capture using Wireshark and a compatible 802.11 adapter in Linux. When viewing the capture, you see an auth req frame and an auth rsp frame. Then you see an assoc req frame and an assoc rsp frame. Shortly after, you see DHCP communications and then ISAKMP protocol packets.

What security solution is represented?

  1. A

    802.1X/EAP-TTLS

  2. B

    WPA2-Personal with AES-CCMP

  3. C

    802.1X/PEAPv0/MS-CHAPv2

  4. D

    EAP-MD5

  5. E

    Open 802.11 authentication with IPSec

Show answer and explanation

Correct answer: E

Question 2 Single choice

What software and hardware tools are used in the process performed to hijack a wireless station from the authorized wireless network onto an unauthorized wireless network?

  1. A

    A low-gain patch antenna and terminal emulation software

  2. B

    MAC spoofing software and MAC DoS software

  3. C

    RF jamming device and a wireless radio card

  4. D

    A wireless workgroup bridge and a protocol analyzer

Show answer and explanation

Correct answer: C

Question 3 Single choice

WLAN protocol analyzers can read and record many wireless frame parameters.

What parameter is needed to physically locate rogue APs with a protocol analyzer?

  1. A

    IP Address

  2. B

    Noise floor

  3. C

    RSN IE

  4. D

    SSID

  5. E

    Signal strength

  6. F

    BSSID

Show answer and explanation

Correct answer: E

Question 4 Single choice

The IEEE 802.11 standard defined Open System authentication as consisting of two auth frames and two assoc frames.
In a WPA2-Enterprise network, what process immediately follows the 802.11 association procedure?

  1. A

    802.1X/ EAP authentication

  2. B

    Group Key Handshake

  3. C

    DHCP Discovery

  4. D

    RADIUS shared secret lookup

  5. E

    4-Way Handshake

  6. F

    Passphrase-to-PSK mapping

Show answer and explanation

Correct answer: A

Question 5 Single choice

After completing the installation of a new overlay WIPS for the purpose of rogue detection and security monitoring at your corporate headquarters, what baseline function MUST be performed in order to identify the security threats?

  1. A

    Separate security profiles must be defined for network operation in different regulatory domains.

  2. B

    WLAN devices that are discovered must be classified (rogue, authorized, neighbor, etc.) and a WLAN policy must define how to classify new devices.

  3. C

    Upstream and downstream throughput thresholds must be specified to ensure that service-level agreements are being met.

  4. D

    Authorized PEAP usernames must be added to the WIPS server's user database.

Show answer and explanation

Correct answer: B

Question 6 Single choice

For a WIPS system to identify the location of a rogue WLAN device using location pattering (RF fingerprinting), what must be done as part of the WIPS installation?

  1. A

    A location chipset (GPS) must be installed with it.

  2. B

    At least six antennas must be installed in each sector.

  3. C

    The RF environment must be sampled during an RF calibration process.

  4. D

    All WIPS sensors must be installed as dual-purpose (AP/sensor) devices.

Show answer and explanation

Correct answer: C

Question 7 Single choice

A WLAN consultant has just finished installing a WLAN controller with 15 controller-based APs. Two SSIDs with separate VLANs are configured for this network, and both VLANs are configured to use the same RADIUS server. The SSIDs are configured as follows:

SSID Blue - VLAN 10 - Lightweight EAP (LEAP) authentication - CCMP cipher suite
SSID Red - VLAN 20 - PEAPv0/EAP-TLS authentication - TKIP cipher suite The consultant's computer can successfully authenticate and browse the Internet when using the Blue SSID. The same computer cannot authenticate when using the Red SSID.

What is a possible cause of the problem?

  1. A

    The consultant does not have a valid Kerberos ID on the Blue VLAN.

  2. B

    The client does not have a proper certificate installed for the tunneled authentication within the established TLS tunnel.

  3. C

    The TKIP cipher suite is not a valid option for PEAPv0 authentication.

  4. D

    The Red VLAN does not use server certificate, but the client requires one.

Show answer and explanation

Correct answer: B

Question 8 Single choice

As the primary security engineer for a large corporate network, you have been asked to author a new security policy for the wireless network. While most client devices support 802.1X authentication, some legacy devices still only support passphrase/PSK-based security methods.

When writing the 802.11 security policy, what password-related items should be addressed?

  1. A

    Certificates should always be recommended instead of passwords for 802.11 client authentication.

  2. B

    Password complexity should be maximized so that weak WEP IV attacks are prevented.

  3. C

    Static passwords should be changed on a regular basis to minimize the vulnerabilities of a PSK-based authentication.

  4. D

    EAP-TLS must be implemented in such scenarios.

  5. E

    MS-CHAPv2 passwords used with EAP/PEAPv0 should be stronger than typical WPA2-PSK passphrases.

Show answer and explanation

Correct answer: C

Question 9 Single choice

You manage a wireless network that services 200 wireless users. Your facility requires 20 access points, and you have installed an IEEE 802.11-compliant implementation of 802.1X/LEAP with AES-CCMP as an authentication and encryption solution.
In this configuration, the wireless network is initially susceptible to what type of attack?

  1. A

    Offline dictionary attacks

  2. B

    Application eavesdropping

  3. C

    Session hijacking

  4. D

    Layer 3 peer-to-peer

  5. E

    Encryption cracking

Show answer and explanation

Correct answer: A

Question 10 Single choice

In an IEEE 802.11-compliant WLAN, when is the 802.1X Controlled Port placed into the unblocked state?

  1. A

    After EAP authentication is successful

  2. B

    After Open System authentication

  3. C

    After the 4-Way Handshake

  4. D

    After any Group Handshake

Show answer and explanation

Correct answer: A