Courseiva
Advanced Topics: Wireless, Cloud, IoT, CryptographymediumMultiple ChoiceObjective-mapped

CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography

During a penetration test, an ethical hacker runs the following command: aireplay-ng -0 5 -a 00:11:22:33:44:55 -c 66:77:88:99:AA:BB wlan0mon. What is the immediate effect of this command?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

It forces the client to disconnect and reconnect, capturing the WPA handshake

The -0 flag sends deauthentication packets to force a client to reconnect, enabling capture of the WPA handshake.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • It performs a WEP injection attack to generate traffic

    Why it's wrong here

    The `aireplay-ng -0` command is specifically designed for sending deauthentication frames, not for WEP injection. WEP injection attacks, which aim to generate new Initialization Vectors (IVs) for cracking, typically utilize different `aireplay-ng` flags such as `-2` for interactive packet replay or `-3` for ARP request replay. These methods focus on replaying or injecting specific types of packets to increase data traffic, which is distinct from simply disconnecting a client.

  • It cracks the pre-shared key using a dictionary

    Why it's wrong here

    Cracking a pre-shared key using a dictionary is a post-capture process, not an action performed by `aireplay-ng -0`. This command's sole function is to send deauthentication frames, forcing a client offline. The actual dictionary attack, which attempts to guess the PSK by comparing captured handshake hashes against a list of common passwords, is executed by dedicated cracking tools like `aircrack-ng` or `hashcat` after a valid WPA/WPA2 4-way handshake has been successfully recorded.

  • It forces the client to disconnect and reconnect, capturing the WPA handshake

    Why this is correct

    The `aireplay-ng -0` command executes a deauthentication attack by sending specially crafted deauthentication frames to a target client or broadcast to all clients associated with an access point. This action forcibly disconnects the client from the Wi-Fi network. When the client automatically attempts to re-establish its connection, it performs the crucial WPA/WPA2 4-way handshake with the access point, which can then be captured by a monitoring tool like `airodump-ng` for subsequent offline cracking attempts.

  • It initiates a brute force attack on the WPS PIN

    Why it's wrong here

    Initiating a brute force attack on a WPS PIN is a distinct process from sending deauthentication frames, and `aireplay-ng -0` is not designed for this purpose. WPS attacks exploit vulnerabilities in the Wi-Fi Protected Setup protocol, typically involving a systematic guessing of the 8-digit PIN. Tools specifically engineered for this task, such as `Reaver` or `Bully`, are used to target WPS-enabled access points by attempting numerous PIN combinations, leveraging the protocol's response mechanisms.

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.