Courseiva

CCNA Wireless Network Security Questions

14 questions · Wireless Network Security · All types, answers revealed

1
Multi-Selectmedium

A security engineer is reviewing the WLAN configuration of a small business that uses WPA2-Personal. The owner wants to raise resistance to offline dictionary attacks against the preshared key without replacing all client hardware. Which two changes best accomplish this goal? (Choose two.)

Select 2 answers
A.Enable 802.11w Management Frame Protection on the SSID to prevent capture of the four-way handshake.
B.Disable the SSID broadcast and enable MAC address filtering to prevent attackers from capturing the handshake.
C.Migrate the SSID to WPA3-SAE so the authentication exchange uses a simultaneous authentication of equals handshake resistant to offline guessing.
D.Configure the AP to use TKIP instead of CCMP so that the captured handshake cannot be decrypted.
E.Replace the human-readable preshared key with a long, randomly generated passphrase of at least 20 characters stored in the client profile.
AnswersC, E

WPA3-SAE replaces the PSK four-way handshake with a Dragonfly-based exchange that provides forward secrecy and resists passive offline dictionary attacks. An eavesdropper cannot capture a handshake and test candidate passphrases offline against it. This directly raises resistance to dictionary attacks, and WPA3-capable hardware can often be enabled through firmware or a controller profile update rather than a full replacement.

Why this answer

Offline dictionary attacks against WPA2-Personal succeed by deriving the PMK from a guessable passphrase and testing it against a captured handshake. Migrating to WPA3-SAE removes that offline attack path, and using a long random passphrase increases entropy so any captured material is impractical to crack. The two measures reinforce each other.

Exam trap

The trap here is assuming that hiding the SSID or enabling management frame protection prevents handshake capture, when neither changes the entropy of the preshared key or the offline attack model.

2
MCQmedium

An administrator observes unauthorized devices connecting to an enterprise wireless network using WPA2-Personal. Which mitigation strategy best prevents credential sharing and ensures unique authentication for every employee?

A.Implement MAC address filtering on all wireless access points.
B.Transition to WPA2-Enterprise utilizing 802.1X authentication with EAP-TLS.
C.Increase the PSK complexity to a 64-character alphanumeric string.
D.Enable hidden SSIDs to prevent unauthorized discovery.
AnswerB

WPA2-Enterprise leverages 802.1X, which requires unique authentication per user, typically via certificates or domain credentials. This approach prevents credential sharing because each session is cryptographically bound to an individual identity, allowing administrators to revoke specific access without impacting the entire wireless network architecture or changing shared passwords.

Why this answer

Moving from WPA2-Personal to WPA2-Enterprise (802.1X) forces each user to authenticate against a central RADIUS server using unique credentials. This eliminates the risk of shared PSKs, which are easily compromised when employees leave or share them. This transition is a foundational requirement for securing enterprise wireless environments and ensuring accountability through centralized logging and per-user access control.

Exam trap

Candidates mistakenly suggest changing the WPA2 pre-shared key frequently or implementing MAC filtering, failing to recognize that only enterprise 802.1X resolves credential sharing.

3
Multi-Selecthard

Which THREE of the following actions are considered best practices when hardening an enterprise wireless infrastructure?

Select 3 answers
A.Disable WPS on all wireless access points.
B.Implement WPA3 or WPA2-Enterprise with 802.1X.
C.Enable SSID hiding to conceal the network.
D.Deploy a WIPS for continuous monitoring and rogue detection.
E.Use WEP for legacy hardware compatibility.
AnswersA, B, D

WPS is inherently insecure due to design flaws in the PIN exchange process. Disabling it completely eliminates this attack vector, which is a mandatory step for any secure deployment. Failure to disable WPS leaves the network vulnerable to rapid credential recovery through automated brute-force tools.

Why this answer

Hardening a wireless network requires a layered defense approach. Disabling unused features like WPS prevents direct exploitation, implementing WPA3 or WPA2-Enterprise ensures strong cryptographic bounds, and using a Wireless Intrusion Prevention System (WIPS) allows for the continuous monitoring and mitigation of rogue devices. These three steps cover the primary vectors of wireless attack: protocol flaws, weak authentication, and unauthorized infrastructure deployment.

Exam trap

Candidates often select 'Disable SSID broadcasting' as a best practice, which is ineffective security through obscurity, rather than focusing on robust authentication like 802.1X or WPA3.

4
MCQmedium

A hospital's wireless network uses WPA2-Enterprise with PEAP-MSCHAPv2. A security engineer discovers that an attacker can capture a client's authentication exchange and crack the password offline. Which change most directly mitigates this specific attack?

A.Deploy Protected Management Frames (PMF) on all access points.
B.Enable 802.11w on the wireless controller.
C.Configure EAP-TLS with client certificates for all wireless clients.
D.Increase the WPA2 pre-shared key length to 64 characters.
AnswerC

PEAP-MSCHAPv2 is vulnerable to offline dictionary attacks because the captured MSCHAPv2 exchange can be cracked without further interaction. EAP-TLS replaces password-based inner authentication with mutual certificate authentication, so there is no crackable password hash. This directly eliminates the attack vector while preserving WPA2-Enterprise. It is the most targeted mitigation for the described offline cracking scenario.

Why this answer

PEAP-MSCHAPv2 transmits an MSCHAPv2 challenge-response that can be captured and cracked offline because the protocol's DES-based keying is weak and lacks channel binding. Replacing it with EAP-TLS removes the password-derived secret entirely, requiring client certificates for mutual authentication. PMF, 802.11w, and PSK length changes do not alter the inner EAP method, so they leave the offline cracking vulnerability intact.

Exam trap

The trap here is assuming that enabling Protected Management Frames or 802.11w hardens the authentication exchange, when it only protects management frames and leaves the crackable MSCHAPv2 handshake untouched.

5
MCQmedium

A financial services firm deploys 802.1X with EAP-TLS on its corporate WLAN. During an assessment, a consultant captures the 802.11 four-way handshake and observes that the attacker cannot derive the PMK because the exchange never leaves the client and RADIUS-issued credentials exposed. Which property of EAP-TLS best explains why this capture alone cannot be used to impersonate a legitimate client?

A.EAP-TLS encrypts the entire four-way handshake inside the TLS tunnel, so the ANonce and SNonce are never visible to a passive observer.
B.EAP-TLS performs mutual authentication using X.509 client and server certificates, so no reusable password-derived secret traverses the wireless medium.
C.EAP-TLS relies on PEAP inner-method tunneling, which wraps the client credential exchange in a protected TLS channel so offline dictionary attacks are impossible.
D.EAP-TLS uses a per-session PSK that the RADIUS server generates and transmits to the client over the encrypted tunnel, so each session key is unique and unrecoverable from the capture.
AnswerB

EAP-TLS authenticates both the supplicant and the authentication server with X.509 certificates and completes a TLS tunnel whose keys never expose a shared password. An attacker capturing the four-way handshake only obtains the ANonce, SNonce, and MIC values tied to that session, which cannot be replayed to derive the PMK for a new association, so impersonation fails without the client's private key.

Why this answer

EAP-TLS bases authentication on mutual X.509 certificate exchange, so neither a password nor a shared secret crosses the air. A captured four-way handshake yields only session-specific values that cannot be replayed or brute-forced into the PMK. Impersonation would require possession of the legitimate client's private key, which the passive capture does not provide.

Exam trap

The trap here is assuming that capturing the four-way handshake always yields crackable key material, which only holds for password-derived methods like WPA2-Personal or PEAP-MSCHAPv2.

6
MCQhard

A hospital's wireless intrusion prevention system reports that a nearby attacker is broadcasting beacon frames that clone the SSID and BSSID of the hospital's legitimate access point at a higher signal strength, luring staff laptops to associate with the attacker's hardware. Which attack is being described, and which defense most directly addresses it?

A.A deauthentication flood; enabling Management Frame Protection forces the attacker's forged frames to be discarded by clients.
B.A MAC spoofing attack; deploying 802.1X with MAC authentication bypass on switch ports eliminates the rogue association.
C.An evil twin attack; requiring server certificate validation in the supplicant profile prevents clients from trusting the rogue AP.
D.A karma attack; disabling the SSID broadcast on legitimate APs prevents clients from probing for and joining the rogue device.
AnswerC

An evil twin impersonates a legitimate AP by cloning its SSID and BSSID, and a stronger signal persuades clients to associate. In WPA2/WPA3-Enterprise, the rogue cannot complete the TLS handshake without a certificate the client trusts, so enforcing server certificate validation in the supplicant stops the association. This directly defeats the impersonation rather than merely detecting it after the fact.

Why this answer

Cloning an AP's SSID and BSSID with a stronger signal to attract clients is an evil twin attack. In an enterprise deployment the rogue cannot present a certificate signed by the trusted CA, so configuring the supplicant to validate the RADIUS server certificate causes the association to fail. Detection alone is weaker than preventing the trust decision.

Exam trap

The trap here is treating a rogue AP that merely broadcasts a matching SSID as harmless reconnaissance, when the cloned BSSID plus stronger signal is what drives client association.

7
MCQmedium

A security auditor notices that wireless clients are frequently disconnected by de-authentication frames that contain a spoofed MAC address of the access point. What is the auditor witnessing?

A.A standard re-keying process defined by WPA2 standards.
B.A de-authentication Denial of Service (DoS) attack.
C.An automated load balancing mechanism on the AP.
D.A probe response flood from an adjacent network.
AnswerB

De-authentication attacks exploit the lack of management frame integrity in older 802.11 standards. By spoofing the AP's address, the attacker forces clients to drop their connection. This is a common method for disrupting service or preparing a target for an Evil Twin or packet interception attack.

Why this answer

This behavior is characteristic of an 802.11 de-authentication attack. By sending spoofed management frames that appear to originate from the legitimate access point, an attacker can force clients to disconnect. This is often a precursor to forcing clients to reconnect to an attacker-controlled Evil Twin AP, enabling the interception of credentials or the execution of further man-in-the-middle attacks.

Exam trap

Students commonly mistake de-authentication attacks for Rogue AP installations or Evil Twin scenarios, confusing the initial disconnection phase with the subsequent credential capture phase.

8
MCQhard

An assessor is standing in a parking lot outside a warehouse and needs to map the coverage footprint and identify all BSSIDs in range, including hidden networks, using a passive approach that does not associate to any AP. Which tool and technique fit this requirement?

A.Deploy a Wireshark capture on the wired uplink of the wireless controller to enumerate all BSSIDs in the coverage area.
B.Use Nmap with the wireless scripts enabled to enumerate BSSIDs by sending 802.11 probe requests from a managed interface.
C.Use Kismet in monitor mode with a supported adapter to passively capture beacon, probe response, and data frames across channels.
D.Run airodump-ng in managed mode and associate to each detected SSID to confirm its encryption type.
AnswerC

Kismet places the adapter in monitor mode, which captures all 802.11 frames on the channel without associating. Beacons and probe responses reveal BSSIDs, SSIDs, channels, and encryption settings, while hidden networks appear through probe responses and data frames. Because no association occurs, the assessor stays passive and avoids altering or alerting the target network.

Why this answer

A passive site survey requires monitor mode so the adapter captures every frame on the channel without associating. Kismet in monitor mode reveals beacons, probe responses, and data frames, exposing BSSIDs, hidden SSIDs through client probing, channels, and encryption. This maps coverage and discovers APs while leaving the target network untouched.

Exam trap

The trap here is confusing a passive monitor-mode survey with tools that require association or operate above the radio layer, which hides beacon-only information such as BSSIDs and hidden networks.

9
MCQhard

A security researcher is evaluating the susceptibility of a WPA3-Personal network to offline dictionary attacks. Which statement accurately describes the resistance provided by WPA3-SAE compared to WPA2-PSK?

A.WPA3-SAE still allows offline dictionary attacks but requires more computational effort due to stronger encryption.
B.WPA3-SAE requires a captive portal to prevent offline attacks, as it does not encrypt management frames.
C.WPA3-SAE prevents offline dictionary attacks by using a simultaneous authentication of equals handshake that does not expose a crackable hash.
D.WPA3-SAE uses the same 4-way handshake as WPA2-PSK but with a longer key, making offline attacks infeasible.
AnswerC

WPA3-SAE uses a Dragonfly handshake that provides forward secrecy and resists offline dictionary attacks. Even if an attacker captures the handshake, they cannot perform an offline brute-force because the exchange does not reveal a password-derived hash that can be tested without interacting with the AP. This is a key improvement over WPA2-PSK, which is vulnerable to offline cracking.

Why this answer

WPA3-SAE employs the Dragonfly handshake, which provides forward secrecy and prevents offline dictionary attacks by ensuring that the password is not exposed in a crackable form. An attacker must interact with the AP for each guess, making brute-force impractical. WPA2-PSK's 4-way handshake exposes a hash that can be cracked offline.

The other options mischaracterize SAE's design or confuse it with unrelated features.

Exam trap

The trap here is thinking that WPA3-SAE merely strengthens encryption or lengthens keys, when its core advantage is the Dragonfly handshake that eliminates the offline crackable hash.

10
Multi-Selecthard

Which TWO of the following statements are true regarding the use of WPA3 compared to WPA2?

Select 2 answers
A.WPA3 uses SAE to replace the vulnerable WPA2 PSK exchange.
B.WPA3 is fully backward compatible with all WEP-based devices.
C.WPA3 mandates the use of Protected Management Frames (PMF).
D.WPA3 removes the requirement for 802.1X authentication entirely.
E.WPA3 encryption is strictly limited to 64-bit keys.
AnswersA, C

SAE (Simultaneous Authentication of Equals) provides stronger protection than the PSK mechanism used in WPA2. It defends against offline dictionary attacks because the key exchange does not rely on a simple hash of the password, preventing attackers from capturing the handshake to crack it later.

Why this answer

WPA3 introduces significant security improvements over WPA2. SAE (Simultaneous Authentication of Equals) replaces the vulnerable PSK exchange, providing forward secrecy and protection against offline dictionary attacks. Additionally, WPA3 mandates Protected Management Frames (PMF), which prevents the de-authentication attacks that plague WPA2.

These enhancements make WPA3 the current standard for protecting wireless networks against common interception and session-hijacking techniques.

Exam trap

Candidates often assume WPA3 replaces WPA2-Enterprise or incorrectly believe that WPA3 makes all previous security protocols redundant, missing that WPA3 specifically addresses PSK weaknesses and management frame vulnerabilities.

11
MCQeasy

A retail chain wants to let customers join a guest WLAN without sharing the corporate preshared key, while still keeping guest traffic isolated from point-of-sale systems. Which design best meets these requirements?

A.Broadcast the corporate SSID with WPA3-SAE and give customers a rotating guest passphrase that changes weekly.
B.Deploy the guest network on the same SSID as corporate users and rely on 802.1X to assign guests a restricted role after authentication.
C.Enable a hidden guest SSID using WEP with a shared key so customers can connect without configuration changes.
D.Configure a separate guest SSID mapped to a dedicated VLAN with client isolation enabled and no route to internal subnets.
AnswerD

A distinct guest SSID bound to its own VLAN keeps guest traffic on a segmented broadcast domain, and client isolation prevents guests from reaching each other. With no routing or ACL permitting access to internal subnets, point-of-sale systems stay unreachable. This satisfies open or captive-portal guest access without distributing the corporate preshared key, which remains protected for internal users.

Why this answer

Guest access is best delivered on its own SSID mapped to a segmented VLAN with client isolation and no internal routing. This keeps the corporate preshared key private, prevents guest-to-guest and guest-to-internal access, and protects point-of-sale systems through network segmentation rather than relying on the guest credential.

Exam trap

The trap here is believing that hiding the SSID or rotating a guest passphrase provides isolation, when only VLAN segmentation and firewall policy actually separate guest traffic from internal systems.

12
MCQmedium

A security analyst at a financial firm is reviewing wireless traffic captured near the executive conference room. The capture shows a flood of 802.11 management frames with source addresses set to the company's legitimate AP MAC address, but the frames are not encrypted and are arriving at a high rate. Which type of attack is most likely occurring?

A.A deauthentication flood using spoofed management frames.
B.A rogue access point broadcasting a duplicate SSID to lure clients.
C.A KRACK key reinstallation attack against the WPA2 four-way handshake.
D.A WPA3 Dragonblood downgrade attack forcing the use of WPA2.
AnswerA

The flood of unencrypted 802.11 management frames with a spoofed AP MAC address is characteristic of a deauthentication attack. These frames are sent to disconnect clients from the legitimate AP, often as a precursor to an evil twin or capture of the WPA handshake. The high rate and spoofed source confirm this is not normal traffic.

Why this answer

The flood of unencrypted 802.11 management frames with a spoofed AP MAC address is a classic deauthentication attack. Attackers use this to disconnect clients from the legitimate AP, often to capture the WPA handshake or to force clients to connect to a rogue AP. The high rate and spoofed source distinguish it from other wireless attacks that manipulate encrypted frames or handshake processes.

Exam trap

The trap here is confusing a deauthentication flood with a KRACK attack or a rogue AP, because all can disrupt wireless connectivity, but only the flood uses spoofed management frames at a high rate.

13
MCQeasy

A security administrator is configuring a new wireless intrusion prevention system (WIPS) for a corporate campus. The administrator wants the WIPS to automatically contain an unauthorized access point that is broadcasting the corporate SSID. Which WIPS capability should be enabled to achieve this?

A.Location tracking of wireless clients.
B.Wireless intrusion detection with alerting only.
C.Spectrum analysis to identify interference sources.
D.Rogue AP containment via over-the-air deauthentication and disassociation frames.
AnswerD

WIPS can automatically contain a rogue AP by sending deauthentication and disassociation frames to clients connected to that AP, effectively disconnecting them. This is a standard containment method. It disrupts the rogue AP's ability to serve clients. The administrator should enable this containment feature to automatically neutralize the threat without manual intervention, aligning with the scenario's requirement.

Why this answer

Automatic rogue AP containment in a WIPS works by sending deauthentication and disassociation frames to clients associated with the rogue device, preventing them from using it. This meets the requirement for automatic neutralization. Alerting, spectrum analysis, and location tracking are valuable but do not provide containment.

Enabling containment is the direct action that achieves the goal.

Exam trap

The trap here is confusing detection with prevention; a WIPS that only alerts does not automatically contain a rogue AP, even though it identifies it.

14
MCQhard

Refer to the exhibit. Which configuration setting poses the most significant risk to the wireless network environment?

A.Channel 1 selection is a performance concern.
B.WPS enabled allows for PIN-based brute-force attacks.
C.WPA2-PSK is insufficient for modern enterprise needs.
D.Management Frame Protection is disabled.
AnswerB

WPS (Wi-Fi Protected Setup) is highly insecure because the PIN validation process is flawed. Attackers can brute-force the PIN in small segments, eventually retrieving the network PSK. This vulnerability exists regardless of how strong the actual WPA2 password is, making it a critical security risk for any network.

Why this answer

The exhibit shows WPS enabled on a WPA2-PSK network. WPS is notoriously vulnerable to brute-force attacks against its 8-digit PIN, which can be cracked in hours, revealing the underlying WPA2 passphrase. Disabling WPS is a standard security requirement because the protocol's design flaw allows for efficient recovery of the network key regardless of the passphrase's complexity, rendering the PSK security model entirely ineffective.

Exam trap

Candidates often confuse WPS vulnerabilities with standard WPA2 passphrase complexity issues, incorrectly assuming a strong pre-shared key mitigates an enabled Wi-Fi Protected Setup PIN flaw.

Ready to test yourself?

Try a timed practice session using only Wireless Network Security questions.