Skip to main content

CWSP-207 Real Exam Questions

Certified Wireless Security Professional

139 questions available · Page 1 of 14

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Multiple choice

Wireless Intrusion Prevention Systems (WIPS) are used for what purposes? (Choose 3)

  1. A

    Performance monitoring and troubleshooting

  2. B

    Enforcing wireless network security policy

  3. C

    Detecting and defending against eavesdropping attacks

  4. D

    Security monitoring and notification

  5. E

    Preventing physical carrier sense attacks

  6. F

    Classifying wired client devices

Show answer and explanation

Correct answers: A, B, D

Question 2 Multiple choice

When TKIP is selected as the pairwise cipher suite, what frame types may be protected with data confidentiality? (Choose 2)

  1. A

    Robust broadcast management

  2. B

    Robust unicast management

  3. C

    Control

  4. D

    Data

  5. E

    ACK

  6. F

    QoS Data

Show answer and explanation

Correct answers: D, F

Question 3 Single choice

You are configuring seven APs to prevent common security attacks. The APs are to be installed in a small business and to reduce costs, the company decided to install all consumer-grade wireless routers. The wireless routers will connect to a switch, which connects directly to the Internet connection providing 50
Mbps of Internet bandwidth that will be shared among 53 wireless clients and 17 wired clients.
To ensure the wireless network is as secure as possible from common attacks, what security measure can you implement given only the hardware referenced?

  1. A

    WPA-Enterprise

  2. B

    802.1X/EAP-PEAP

  3. C

    WPA2-Enterprise

  4. D

    WPA2-Personal

Show answer and explanation

Correct answer: D

Question 4 Single choice

What WLAN client device behavior is exploited by an attacker during a hijacking attack?

  1. A

    When the RF signal between a client and an access point is disrupted for more than a few seconds, the client device will attempt to associate to an access point with better signal quality.

  2. B

    When the RF signal between a client and an access point is lost, the client will not seek to reassociate with another access point until the 120 second hold down timer has expired.

  3. C

    After the initial association and 4-way handshake, client stations and access points do not need to perform another 4-way handshake, even if connectivity is lost.

  4. D

    As specified by the Wi-Fi Alliance, clients using Open System authentication must allow direct client-to-client connections, even in an infrastructure BSS.

  5. E

    Client drivers scan for and connect to access points in the 2.4 GHz band before scanning the 5 GHz band.

Show answer and explanation

Correct answer: A

Question 5 Single choice

You are implementing an 802.11ac WLAN and a WIPS at the same time. You must choose between integrated and overlay WIPS solutions.

Which of the following statements is true regarding integrated WIPS solutions?

  1. A

    Integrated WIPS always perform better from a client throughput perspective because the same radio that performs the threat scanning also services the clients.

  2. B

    Integrated WIPS use special sensors installed alongside the APs to scan for threats.

  3. C

    Many integrated WIPS solutions that detect Voice over Wi-Fi traffic will cease scanning altogether to accommodate the latency sensitive client traffic.

  4. D

    Integrated WIPS is always more expensive than overlay WIPS.

Show answer and explanation

Correct answer: C

Question 6 Single choice

Given: In XYZ's small business, two autonomous 802.11ac APs and 12 client devices are in use with WPA2-Personal.

What statement about the WLAN security of this company is true?

  1. A

    Intruders may obtain the passphrase with an offline dictionary attack and gain network access, but will be unable to decrypt the data traffic of other users.

  2. B

    A successful attack against all unicast traffic on the network would require a weak passphrase dictionary attack and the capture of the latest 4-Way Handshake for each client.

  3. C

    An unauthorized wireless client device cannot associate, but can eavesdrop on some data because WPA2-Personal does not encrypt multicast or broadcast traffic.

  4. D

    An unauthorized WLAN user with a protocol analyzer can decode data frames of authorized users if he captures the BSSID, client MAC address, and a user's 4-Way Handshake.

  5. E

    Because WPA2-Personal uses Open System authentication followed by a 4-Way Handshake, hijacking attacks are easily performed.

Show answer and explanation

Correct answer: B

Question 7 Single choice

An attack is under way on the network. The attack is preventing users from accessing resources required for business operations, but the attacker has not gained access to any files or data.

What kind of attack is described?

  1. A

    Man-in-the-middle

  2. B

    Hijacking

  3. C

    ASLEAP

  4. D

    DoS

Show answer and explanation

Correct answer: D

Question 8 Single choice

Which cryptographic suite is mandatory for Robust Security Networks (RSN)?

  1. A

    TKIP

  2. B

    RC4

  3. C

    CCMP

  4. D

    LEAP

Show answer and explanation

Correct answer: C

Question 9 Multiple choice

A WLAN is implemented using WPA-Personal and MAC filtering.
To what common wireless network attacks is this network potentially vulnerable? (Choose 3)

  1. A

    Offline dictionary attacks

  2. B

    MAC Spoofing

  3. C

    ASLEAP

  4. D

    DoS

Show answer and explanation

Correct answers: A, B, D

Question 10 Single choice

Which EAP method supports password authentication without requiring a server-side certificate?

  1. A

    EAP-TTLS/MSCHAPv2

  2. B

    EAP-TLS

  3. C

    EAP-FAST

  4. D

    PEAPv1/EAP-GTC

Show answer and explanation

Correct answer: C