โ† All Certified Ethical Hacker Flashcard Decks

Wireless and IoT Security Flashcards

7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Wireless and IoT Security flashcards as text
  1. The KRACK attack against WPA2 exploits a flaw in which part of the protocol?

    Answer: The four-way handshake key reinstallation

    KRACK forces nonce reuse by replaying message 3 of the four-way handshake, reinstalling an already-in-use key.

  2. Which improvement does WPA3 introduce to resist offline dictionary attacks on the password?

    Answer: Simultaneous Authentication of Equals (SAE)

    WPA3 uses SAE (Dragonfly handshake), which prevents offline dictionary attacks even with weak passwords.

  3. An IoT device ships with the default credentials admin/admin and exposes Telnet. Which botnet famously exploited this pattern?

    Answer: Mirai

    The Mirai botnet scanned for IoT devices with default Telnet credentials to build a massive DDoS network.

  4. Which short-range wireless protocol is commonly targeted in IoT attacks and operates in the 2.4 GHz band using 16 channels?

    Answer: Zigbee

    Zigbee operates in the 2.4 GHz band with 16 channels and is widely used in smart-home IoT devices.

  5. What is 'bluesnarfing'?

    Answer: Unauthorized access to data on a Bluetooth device

    Bluesnarfing is the unauthorized access and theft of information from a Bluetooth-enabled device.

  6. Which OWASP IoT Top 10 issue does using hardcoded passwords in firmware represent?

    Answer: Weak, guessable, or hardcoded passwords

    Hardcoded credentials fall under the OWASP IoT category of weak, guessable, or hardcoded passwords.

  7. Which tool would a tester most likely use to perform a software-defined radio (SDR) analysis of IoT RF signals?

    Answer: HackRF with GNU Radio

    HackRF paired with GNU Radio is a common SDR platform for capturing and analyzing IoT radio signals.