CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography
Which of the following is a recommended countermeasure against WPA2 KRACK attacks?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Patch all clients and access points
KRACK attacks exploit vulnerabilities in the WPA2 4-way handshake key reinstallation. The primary fix is to install security patches on clients and APs that implement the IEEE 802.11 standard update. Disabling WPS does not prevent KRACK, and switching to WEP is less secure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable MAC filtering
Why it's wrong here
Enabling MAC filtering is an ineffective countermeasure because it operates by restricting network access based on hardware addresses, which are easily spoofed by an attacker. This method does not address the fundamental cryptographic flaws within the WPA2 4-way handshake that Key Reinstallation Attacks (KRACK) exploit, as KRACK targets the key management process itself, not unauthorized client access based on MAC addresses.
- ✓
Patch all clients and access points
Why this is correct
Patching all clients and access points is the recommended and most effective countermeasure against Key Reinstallation Attacks (KRACK). These patches specifically modify the WPA2 protocol's 4-way handshake implementation to prevent the reinstallation of an all-zero or previously used cryptographic key. By fixing this logic flaw, devices can properly establish and maintain secure, unique session keys, thereby mitigating the attack vector.
- ✗
Disable WPS
Why it's wrong here
Disabling Wi-Fi Protected Setup (WPS) does not mitigate Key Reinstallation Attacks (KRACK) because WPS is a separate feature designed for simplified network setup, known for its own distinct PIN brute-force vulnerabilities. KRACK, conversely, exploits a fundamental flaw in the WPA2 protocol's 4-way handshake, which is used to establish cryptographic keys for *all* WPA2 connections, regardless of WPS status. Therefore, addressing WPS does not impact the KRACK vulnerability.
- ✗
Switch to WEP encryption
Why it's wrong here
Switching to WEP encryption is a highly detrimental and insecure countermeasure, as WEP (Wired Equivalent Privacy) is an outdated and fundamentally broken security protocol. Its reliance on a static, short initialization vector and the weak RC4 stream cipher makes it trivial for attackers to crack the encryption key within minutes using readily available tools. Adopting WEP would expose the network to far greater and more easily exploitable vulnerabilities than those presented by KRACK in WPA2.
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.