CWNA Risk Assessment & Management 2 — Questions and Answers
Question 1: A risk assessment reveals that a wireless network in a hospital has a high likelihood of interference from medical devices. What risk treatment option involves accepting the risk without mitigation?
- Risk avoidance
- Risk transference
- Risk acceptance (Correct answer)
- Risk mitigation
Correct answer: Risk acceptance
Risk acceptance means acknowledging the risk and choosing to operate without implementing controls, often because the cost of mitigation exceeds the potential loss.
Question 2: Which quantitative risk metric expresses the expected monetary loss from a specific threat occurring once?
- Annual Loss Expectancy (ALE)
- Single Loss Expectancy (SLE) (Correct answer)
- Asset Value (AV)
- Exposure Factor (EF)
Correct answer: Single Loss Expectancy (SLE)
Single Loss Expectancy (SLE) = Asset Value × Exposure Factor and represents the expected dollar loss per individual occurrence of a threat.
Question 3: During a wireless site survey, an assessor discovers rogue APs transmitting on DFS channels. Why is this particularly concerning from a risk perspective?
- DFS channels have lower throughput than non-DFS channels
- Rogue APs on DFS channels can cause radar interference and regulatory violations (Correct answer)
- DFS channels are reserved exclusively for enterprise use
- APs on DFS channels cannot be detected by wireless scanners
Correct answer: Rogue APs on DFS channels can cause radar interference and regulatory violations
DFS channels require radar detection compliance; rogue APs operating on these channels risk causing interference with radar systems and violating FCC regulations.
Question 4: A company wants to reduce the impact of a successful evil twin attack against its employees. Which control most directly addresses this risk?
- Deploying a wireless intrusion prevention system (WIPS)
- Requiring mutual authentication via 802.1X/EAP (Correct answer)
- Increasing beacon interval on legitimate APs
- Reducing transmit power of corporate APs
Correct answer: Requiring mutual authentication via 802.1X/EAP
Mutual authentication in 802.1X/EAP requires both the client and server to prove their identity, preventing clients from connecting to fraudulent APs that cannot present a valid server certificate.
Question 5: An organization's risk register shows a vulnerability rated 'Critical' with a threat likelihood of 'Low.' How should this be prioritized relative to a 'High' vulnerability with 'High' likelihood?
- The Critical/Low risk always takes priority due to severity
- The High/High risk typically has a higher overall risk score (Correct answer)
- Both should receive identical remediation timelines
- Likelihood is irrelevant when severity is Critical
Correct answer: The High/High risk typically has a higher overall risk score
Risk = Likelihood × Impact, so a High severity with High likelihood usually produces a higher calculated risk score than Critical severity with Low likelihood.
Question 6: Which wireless security framework mandates a formal risk assessment as part of compliance for organizations handling payment card data?
- IEEE 802.11i
- PCI DSS (Correct answer)
- NIST SP 800-53
- ISO 27001
Correct answer: PCI DSS
PCI DSS Requirement 12.2 explicitly requires organizations to implement a risk assessment process at least annually and after significant changes to the environment.
Question 7: A penetration tester identifies that WPA2-Personal is used across a large enterprise with hundreds of employees. What is the primary risk this configuration introduces?
- Increased RF interference from TKIP encryption overhead
- A compromised PSK exposes all network traffic and cannot be scoped to individual users (Correct answer)
- WPA2-Personal does not support AES-CCMP encryption
- RADIUS servers cannot be used alongside WPA2-Personal
Correct answer: A compromised PSK exposes all network traffic and cannot be scoped to individual users
With a shared PSK, any compromised credential grants access to the entire wireless network, and individual accountability or per-user revocation is not possible.
A risk assessment reveals that a wireless network in a hospital has a high likelihood of interference from medical devices.
What risk treatment option involves accepting the risk without mitigation?