โ† All Certified Ethical Hacker Flashcard Decks

Wireless and IoT Security Flashcards

6 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Wireless and IoT Security flashcards as text
  1. What is the difference between WPA2 and WPA3 security protocols?

    Answer: WPA3 uses SAE (Simultaneous Authentication of Equals) replacing WPA2's PSK, providing better protection against offline attacks

    WPA3 replaces WPA2's Pre-Shared Key (PSK) with Simultaneous Authentication of Equals (SAE/Dragonfly), providing forward secrecy, protection against offline dictionary attacks, and stronger encryption (192-bit in Enterprise mode).

  2. What is an evil twin attack in wireless security?

    Answer: Creating a rogue access point mimicking a legitimate network to intercept traffic

    An evil twin creates a rogue Wi-Fi access point with the same SSID and appearance as a legitimate network, tricking users into connecting to it, allowing the attacker to intercept all transmitted data.

  3. What is WPS (Wi-Fi Protected Setup) and why is it considered a security risk?

    Answer: A simplified connection method using PINs that is vulnerable to brute-force attacks due to the PIN's design flaw

    WPS allows easy device connection via an 8-digit PIN, but a design flaw allows the PIN to be brute-forced in two halves (10,000 + 1,000 attempts) rather than 100 million combinations, making it crackable in hours.

  4. What security risks are specific to IoT devices?

    Answer: Default credentials, lack of encryption, no update mechanism, and large attack surface

    IoT devices commonly have default/hardcoded passwords, lack encryption for communications, have no mechanism for firmware updates, run minimal security software, and create a massive attack surface when deployed at scale.

  5. What is a deauthentication attack in wireless hacking?

    Answer: Sending forged deauth frames to disconnect clients from a legitimate AP, enabling further attacks

    Deauthentication attacks send spoofed deauthentication management frames (which are not encrypted in WPA2) to disconnect clients, enabling capture of the WPA handshake for offline cracking or forcing clients to connect to an evil twin.

  6. What is Bluetooth sniffing and what tool is commonly used?

    Answer: Intercepting Bluetooth communications using tools like Ubertooth to capture and analyze packets

    Bluetooth sniffing captures Bluetooth communications to analyze device pairing, data transfer, and potentially extract sensitive information using specialized tools like Ubertooth One that can monitor all Bluetooth channels.