Courseiva

CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography

A security analyst captures a WPA2 4-way handshake using airodump-ng. Which tool would they most likely use next to attempt to crack the PSK using a wordlist?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Aircrack-ng

Aircrack-ng is the standard tool for cracking WEP/WPA keys from captured packets, including WPA2 handshakes using a dictionary attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • John the Ripper

    Why it's wrong here

    John the Ripper is a powerful, general-purpose password cracking tool primarily used for auditing password security by cracking various hash types (e.g., Unix crypt, Windows NTLM, Kerberos). While it can be adapted to crack WPA/WPA2 PSK hashes if they are first converted into a compatible hash format, it does not directly process the captured 4-way handshake .cap files. Therefore, it's not the most direct or specialized tool for dictionary attacks against raw WPA2 handshakes.

  • ScoutSuite

    Why it's wrong here

    ScoutSuite is an open-source multi-cloud security auditing tool designed to identify misconfigurations and security vulnerabilities within cloud environments such as AWS, Azure, GCP, and Alibaba Cloud. It performs comprehensive checks against various cloud services to generate a security report. Its functionality is entirely focused on cloud infrastructure analysis and has no capabilities related to capturing or cracking wireless network handshakes.

  • Aircrack-ng

    Why this is correct

    Aircrack-ng is a comprehensive suite of tools specifically designed for auditing wireless networks, including capturing and cracking WPA/WPA2 PSK handshakes. It directly processes the captured 4-way handshake file (typically a .cap file) and attempts to crack the Pre-Shared Key (PSK) using dictionary attacks against the cryptographic nonce and EAPOL frames. Its aircrack-ng component is the definitive tool for performing dictionary-based brute-force or wordlist attacks against the captured WPA2 handshake.

  • Reaver

    Why it's wrong here

    Reaver is a specialized tool primarily designed to exploit vulnerabilities in Wi-Fi Protected Setup (WPS) by brute-forcing the WPS PIN. This attack vector bypasses the need to capture a WPA/WPA2 4-way handshake entirely, instead focusing on the WPS protocol's design flaws to recover the WPA/WPA2 passphrase. It does not perform dictionary attacks against captured WPA2 handshakes, making it unsuitable for the scenario described.

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.