Network+ Wireless Security Protocols Flashcards
7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network+ Wireless Security Protocols flashcards as text
Which of the following BEST explains why WEP is considered cryptographically broken?
Answer: Its 24-bit IV is too short, leading to IV reuse and key recovery
WEP's 24-bit initialization vector frequently repeats, allowing statistical attacks that recover the key from captured packets.
Which tunneling EAP method wraps inner authentication protocols inside a TLS tunnel without requiring client-side certificates?
Answer: PEAP
PEAP creates a TLS tunnel using only a server certificate, then passes inner authentication (e.g., MSCHAPv2) securely inside.
An organization wants wireless clients to automatically re-authenticate after 8 hours without user intervention. Which feature should be configured?
Answer: Session timeout on the RADIUS server
A RADIUS session timeout forces clients to re-authenticate after the configured period, enforcing periodic credential validation.
Which wireless security mode provides the WEAKEST protection and should never be used in production environments?
Answer: Open (no authentication)
Open wireless networks transmit all data in cleartext with no authentication, offering zero protection against eavesdropping.
A network technician is troubleshooting a wireless client that can associate with the AP but cannot access network resources. The AP uses WPA2-Enterprise. What is the MOST likely cause?
Answer: Client certificate or RADIUS credentials are invalid
In WPA2-Enterprise, association succeeds but network access requires successful RADIUS authentication, which fails if credentials or certificates are wrong.
What is the key difference between WPA2-Personal and WPA2-Enterprise in terms of key management?
Answer: Personal uses a shared PSK; Enterprise derives unique per-session keys via RADIUS
WPA2-Personal uses a single pre-shared key for all clients, while Enterprise generates unique PMK per session via RADIUS EAP exchange.
Which attack can compromise WPA2-Personal networks by capturing the four-way handshake and then performing offline analysis?
Answer: Dictionary/brute-force attack
Once the four-way handshake is captured, an attacker can run dictionary or brute-force tools offline to guess the PSK.