Wireless Network Hacking Flashcards
7 cards from real CEH practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Wireless Network Hacking flashcards as text
WPA3's Simultaneous Authentication of Equals (SAE) replaces PSK to defend against which specific attack class?
Answer: Offline dictionary and brute-force attacks against captured handshakes
WPA3-SAE (Dragonfly handshake) provides forward secrecy and prevents offline dictionary attacks because the authentication requires real-time interaction with the AP, making captured traffic useless for offline cracking.
The PMKID attack on WPA2 is advantageous over traditional handshake capture because:
Answer: It requires only a single EAPOL frame from the AP and does not require a client to be present
The PMKID attack extracts a cryptographic identifier from a single EAPOL frame sent by the AP, eliminating the need to wait for a client to authenticate, making it faster and more reliable.
Which 802.11 standard introduced both the 2.4 GHz and 5 GHz dual-band capability and commonly achieves speeds up to 600 Mbps using MIMO technology?
Answer: 802.11n
802.11n (Wi-Fi 4) introduced dual-band operation on 2.4 GHz and 5 GHz and uses Multiple-Input Multiple-Output (MIMO) antenna technology to achieve up to 600 Mbps throughput.
A Bluesnarfing attack differs from Bluejacking in that Bluesnarfing:
Answer: Unauthorized access to information on a Bluetooth device such as contacts, calendar, and messages
Bluesnarfing involves unauthorized extraction of data (contacts, messages, calendar entries) from a Bluetooth-enabled device, whereas Bluejacking only sends unsolicited messages.
What is the purpose of configuring a wireless adapter in 'monitor mode' during a wireless assessment?
Answer: To allow the adapter to capture all 802.11 frames in range, including frames not addressed to it
Monitor mode (also called RFMON) allows a wireless adapter to passively capture all 802.11 frames on a channel regardless of the destination address, enabling network analysis and handshake capture.
Which countermeasure is MOST effective at detecting and alerting on rogue access points in an enterprise environment?
Answer: Deploying a Wireless Intrusion Detection/Prevention System (WIDS/WIPS)
A Wireless IDS/IPS continuously monitors the RF environment for unauthorized APs, anomalous management frames, and attack signatures, providing active detection and prevention capabilities.
During a wireless penetration test, you use 'aireplay-ng -0 5 -a [BSSID] -c [client MAC]'. What does the '-0 5' parameter accomplish?
Answer: Sends 5 deauthentication frames to the specified client to force reauthentication
The '-0' flag in aireplay-ng specifies a deauthentication attack, and '5' sets the number of deauth packets to send, forcing the client to disconnect and reconnect so the handshake can be captured.