Wireless and IoT Security Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Wireless and IoT Security flashcards as text
Which attack forces a client to disconnect from an access point so the attacker can capture the WPA2 four-way handshake on reconnection?
Answer: Deauthentication attack
Deauthentication frames knock a client off the AP, forcing a reconnect that reveals the handshake for offline cracking.
What is the primary weakness of WEP that allows its encryption key to be recovered?
Answer: Short, reused initialization vectors (IVs)
WEP's 24-bit IVs are short and frequently reused, enabling statistical attacks like FMS to recover the key.
An attacker sets up a rogue AP with the same SSID as a legitimate corporate network to lure clients. What is this called?
Answer: Evil twin
An evil twin mimics a legitimate AP's SSID to trick users into connecting through the attacker.
Which tool suite is commonly used to capture and crack WPA/WPA2 handshakes?
Answer: Aircrack-ng
Aircrack-ng captures wireless traffic and performs dictionary/brute-force attacks against captured handshakes.
What WPS feature makes it vulnerable to brute-force attacks such as those performed by Reaver?
Answer: The 8-digit PIN validated in two halves
WPS validates the PIN in two halves, drastically reducing the number of guesses needed to brute-force it.
Which encryption protocol replaced TKIP in WPA2 to provide stronger confidentiality?
Answer: CCMP (AES)
WPA2 uses CCMP based on AES, replacing the weaker RC4-based TKIP used in WPA.
What does 'war driving' refer to in wireless security?
Answer: Driving around to locate and map wireless networks
War driving is the practice of mapping and discovering wireless networks while moving through an area, often by car.