Network+ Wireless Security Protocols Flashcards
7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network+ Wireless Security Protocols flashcards as text
Which feature of WPA3-Personal provides forward secrecy, ensuring past session traffic cannot be decrypted even if the passphrase is later compromised?
Answer: SAE with perfect forward secrecy
WPA3-SAE generates a unique session key for every connection, so compromising the passphrase later cannot decrypt previously recorded traffic.
A security auditor finds that a wireless AP still supports WPA/TKIP in mixed mode alongside WPA2/CCMP. What is the risk?
Answer: Clients negotiating TKIP lose WPA2-level security and become vulnerable to TKIP attacks
Mixed mode allows TKIP negotiation, which is cryptographically weak, and an attacker can force TKIP downgrades on connected clients.
Which 802.11 security amendment introduced the RSN (Robust Security Network) and mandated CCMP as the required cipher?
Answer: 802.11i
IEEE 802.11i defined the RSN framework, requiring CCMP/AES and forming the basis of what is marketed as WPA2.
What is the purpose of the PMK (Pairwise Master Key) in WPA2?
Answer: It is derived from the PSK or EAP process and used as the basis for the four-way handshake
The PMK is the top-level key derived from either the PSK or EAP authentication, from which the PTK is generated via the four-way handshake.
An admin wants to segment IoT devices from corporate laptops on the same physical AP. Which wireless feature BEST accomplishes this?
Answer: Multiple SSIDs mapped to separate VLANs
Multiple SSIDs with VLAN tagging allows the AP to logically separate traffic, placing IoT and corporate devices on different network segments.
Which tool is commonly used by penetration testers to capture WPA2 handshakes and perform password cracking on wireless networks?
Answer: Aircrack-ng
Aircrack-ng is a wireless security toolset that can capture the WPA2 four-way handshake and perform dictionary attacks against the captured hash.
Which wireless security configuration is considered a best practice when deploying a guest network?
Answer: Isolated VLAN with captive portal and client isolation enabled
Guest networks should be isolated on a separate VLAN, use a captive portal for access control, and enable client isolation to prevent guest-to-guest attacks.