Wireless and IoT Security Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Wireless and IoT Security flashcards as text
In an enterprise WPA2-Enterprise deployment, which server authenticates users via 802.1X?
Answer: RADIUS server
WPA2-Enterprise uses 802.1X with a RADIUS server to authenticate individual users rather than a shared key.
An attacker captures the PMKID directly from an AP without needing a client. This clientless attack targets which technology?
Answer: WPA/WPA2 with roaming enabled
The PMKID attack extracts a hash from the AP's first handshake message, enabling clientless WPA/WPA2 cracking.
What is the main purpose of MAC address filtering on a wireless network, and why is it weak?
Answer: It restricts which devices connect but MACs can be spoofed
MAC filtering limits which devices may connect, but attackers can sniff and spoof an allowed MAC address.
Which attack involves sending unsolicited messages to nearby Bluetooth devices?
Answer: Bluejacking
Bluejacking sends unsolicited messages to Bluetooth devices, typically as a nuisance rather than data theft.
Bluebugging gives an attacker what capability over a victim's Bluetooth phone?
Answer: Remote control of the device's commands and calls
Bluebugging exploits Bluetooth to gain remote control over the device, allowing calls, messages, and command execution.
Which frequency band is used by most LoRaWAN IoT deployments to achieve long-range, low-power communication?
Answer: Sub-GHz ISM bands (e.g., 868/915 MHz)
LoRaWAN uses sub-GHz ISM bands such as 868 MHz (EU) and 915 MHz (US) for long-range, low-power links.
When extracting firmware from an IoT device for analysis, which tool is commonly used to identify and unpack embedded file systems?
Answer: Binwalk
Binwalk scans firmware images to identify signatures and extract embedded file systems and components.