mediumMultiple Choice
PT0-002 Practice Question: A wireless network test must not disrupt the…
A wireless network test must not disrupt the network. How can the tester crack WPA2 passwords without disruption?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use passive sniffing to capture traffic and crack offline
Passive sniffing captures the WPA2 4-way handshake (or PMKID) from normal client traffic without sending any frames, and the captured handshake is then cracked offline against a wordlist, so the live network is never disrupted. This satisfies the requirement that the test must not disrupt the network. Option A, scanning for rogue access points, is a discovery activity and does not crack WPA2 passwords. Option C, a deauthentication attack, forcibly disconnects clients and is inherently disruptive. Option D, an online brute-force attack against the Wi-Fi password, would generate authentication attempts against the AP, which is disruptive and also impractical due to WPA2's key derivation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Scan for rogue access points
Why it's wrong here
Scanning for rogue access points only inventories unauthorised radios; it captures no WPA2 handshake and yields nothing to crack. It is tempting because scanning is passive and non-disruptive, and it is correct when the objective is rogue-device detection rather than password recovery.
- ✓
Use passive sniffing to capture traffic and crack offline
Why this is correct
Passive sniffing captures the WPA2 four-way handshake without transmitting any frames, so the live network remains untouched — satisfying the non-disruptive constraint. Cracking then occurs offline against the captured handshake, meaning no authentication attempts or deauthentication frames ever reach the access point.
- ✗
Perform a deauthentication attack
Why it's wrong here
Deauthentication forces clients to reconnect and capture a handshake, but it disconnects users, directly violating the no-disruption requirement. It is the standard WPA2 cracking technique and correct when disruption is permitted, such as an authorised engagement with an agreed outage window.
- ✗
Attempt a brute-force attack against the Wi-Fi password
Why it's wrong here
Brute-forcing the Wi-Fi password online requires repeated authentication attempts against the access point, which can lock accounts or flood logs and does not capture a handshake passively. It suits offline cracking of a captured PMKID or handshake, not live non-disruptive testing.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.