Courseiva
Wireless, IoT and Cloud SecurityhardMultiple ChoiceObjective-mapped

CEH Wireless, IoT and Cloud Security Practice Question

During a penetration test of a corporate wireless network, you capture a WPA2 handshake and successfully recover the PSK. Later, you notice that some clients are using WPA3-Personal. Which attack could be used to downgrade a WPA3 client to WPA2 and capture its handshake?

⚠ Common exam trap

EC-Council often tests the misconception that deauthentication alone can force a protocol downgrade, but in WPA3, deauthentication only triggers a reconnection using the same security protocol unless the AP changes its capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Set up a rogue access point broadcasting a WPA2 network with the same SSID, forcing the client to reconnect using WPA2.

WPA3 clients are designed to fall back to WPA2 when the access point only supports WPA2. By setting up a rogue AP with the same SSID but configured for WPA2, the client will attempt to connect using WPA2, allowing you to capture the 4-way handshake and potentially recover the PSK if the same password is used for both security modes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Perform a PMKID attack on the WPA3 client to capture the handshake.

    Why it's wrong here

    The PMKID attack specifically targets WPA2-PSK networks by capturing the Pairwise Master Key Identifier from a single EAPOL frame, which can then be brute-forced offline. WPA3, however, utilizes the Simultaneous Authentication of Equals (SAE) handshake, which is designed to be resistant to offline dictionary attacks and does not transmit a PMKID in a way that can be exploited for offline cracking. Therefore, this attack method is ineffective against WPA3 clients.

  • Use a WPS PIN brute-force attack against the WPA3 client.

    Why it's wrong here

    Wi-Fi Protected Setup (WPS) is a separate protocol designed for easy device connection, often vulnerable to PIN brute-force attacks due to its design flaws. While some WPA3-capable devices might still support WPS for backward compatibility, WPS itself is not an inherent part of WPA3's core security mechanisms and is largely deprecated due to its known vulnerabilities. Attacking WPS would compromise the WPS feature, not directly exploit WPA3's cryptographic handshake or downgrade the WPA3 connection.

  • Send deauthentication packets to the WPA3 client and capture the reconnection handshake.

    Why it's wrong here

    Sending deauthentication packets merely disconnects a client from its current access point, forcing it to reauthenticate. While this can capture a legitimate WPA3 SAE handshake, WPA3's design, particularly its resistance to offline dictionary attacks through SAE, means simply capturing this handshake does not provide an avenue for compromise. The client will attempt to reconnect securely using WPA3, not automatically downgrade its security protocol.

  • Set up a rogue access point broadcasting a WPA2 network with the same SSID, forcing the client to reconnect using WPA2.

    Why this is correct

    A rogue access point (AP) can be configured to mimic the legitimate network's SSID but broadcast a weaker security protocol like WPA2. Many WPA3-capable clients are configured to prefer WPA3 but will fall back to WPA2 if WPA3 is unavailable or if a stronger WPA2 signal appears more legitimate. By deauthenticating the client from the real WPA3 AP, the rogue WPA2 AP can entice the client to connect, effectively downgrading its security and allowing for WPA2-specific attacks.

About these practice questions

This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.