โ† All CEH Flashcard Decks

Wireless Network Hacking Flashcards

7 cards from real CEH practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Wireless Network Hacking flashcards as text
  1. WPA3's Simultaneous Authentication of Equals (SAE) replaces PSK to defend against which specific attack class?

    Answer: Offline dictionary and brute-force attacks against captured handshakes

    WPA3-SAE (Dragonfly handshake) provides forward secrecy and prevents offline dictionary attacks because the authentication requires real-time interaction with the AP, making captured traffic useless for offline cracking.

  2. The PMKID attack on WPA2 is advantageous over traditional handshake capture because:

    Answer: It requires only a single EAPOL frame from the AP and does not require a client to be present

    The PMKID attack extracts a cryptographic identifier from a single EAPOL frame sent by the AP, eliminating the need to wait for a client to authenticate, making it faster and more reliable.

  3. Which 802.11 standard introduced both the 2.4 GHz and 5 GHz dual-band capability and commonly achieves speeds up to 600 Mbps using MIMO technology?

    Answer: 802.11n

    802.11n (Wi-Fi 4) introduced dual-band operation on 2.4 GHz and 5 GHz and uses Multiple-Input Multiple-Output (MIMO) antenna technology to achieve up to 600 Mbps throughput.

  4. A Bluesnarfing attack differs from Bluejacking in that Bluesnarfing:

    Answer: Unauthorized access to information on a Bluetooth device such as contacts, calendar, and messages

    Bluesnarfing involves unauthorized extraction of data (contacts, messages, calendar entries) from a Bluetooth-enabled device, whereas Bluejacking only sends unsolicited messages.

  5. What is the purpose of configuring a wireless adapter in 'monitor mode' during a wireless assessment?

    Answer: To allow the adapter to capture all 802.11 frames in range, including frames not addressed to it

    Monitor mode (also called RFMON) allows a wireless adapter to passively capture all 802.11 frames on a channel regardless of the destination address, enabling network analysis and handshake capture.

  6. Which countermeasure is MOST effective at detecting and alerting on rogue access points in an enterprise environment?

    Answer: Deploying a Wireless Intrusion Detection/Prevention System (WIDS/WIPS)

    A Wireless IDS/IPS continuously monitors the RF environment for unauthorized APs, anomalous management frames, and attack signatures, providing active detection and prevention capabilities.

  7. During a wireless penetration test, you use 'aireplay-ng -0 5 -a [BSSID] -c [client MAC]'. What does the '-0 5' parameter accomplish?

    Answer: Sends 5 deauthentication frames to the specified client to force reauthentication

    The '-0' flag in aireplay-ng specifies a deauthentication attack, and '5' sets the number of deauth packets to send, forcing the client to disconnect and reconnect so the handshake can be captured.