CWNA Risk Assessment & Management 3 — Questions and Answers
Question 1: During a risk analysis, an organization determines its wireless infrastructure has an Asset Value of $200,000 and an Exposure Factor of 40% for a flood threat. What is the SLE?
- $40,000
- $80,000 (Correct answer)
- $120,000
- $200,000
Correct answer: $80,000
SLE = Asset Value × Exposure Factor = $200,000 × 0.40 = $80,000.
Question 2: A CWNA candidate is reviewing threats to a wireless network. Which threat specifically exploits the 802.11 management frame vulnerability to disconnect legitimate clients?
- Eavesdropping attack
- Deauthentication flood attack (Correct answer)
- Kr00k attack
- PMKID attack
Correct answer: Deauthentication flood attack
A deauthentication flood attack sends spoofed management frames to force clients to disconnect, exploiting the lack of authentication in 802.11 management frames prior to 802.11w.
Question 3: An annual risk review shows that a previously identified medium risk has escalated to high due to a new threat actor. What document should be updated to reflect this change?
- Security policy
- Risk register (Correct answer)
- Business continuity plan
- Network diagram
Correct answer: Risk register
The risk register is the living document that tracks identified risks, their ratings, owners, and status, and must be updated whenever risk levels change.
Question 4: A wireless network administrator is tasked with assessing the risk of using WEP on a legacy manufacturing device that cannot be upgraded. Which risk treatment is most appropriate?
- Risk avoidance by decommissioning all legacy devices immediately
- Risk mitigation by isolating the device on a separate VLAN with firewall rules (Correct answer)
- Risk transference by purchasing additional cyber insurance
- Risk acceptance with no additional controls
Correct answer: Risk mitigation by isolating the device on a separate VLAN with firewall rules
Network segmentation isolates the vulnerable device, limiting the blast radius of a potential WEP compromise while allowing the legacy device to remain operational.
Question 5: Which 802.11 amendment introduced Management Frame Protection (MFP) to mitigate deauthentication and disassociation attacks?
- 802.11n
- 802.11ac
- 802.11w (Correct answer)
- 802.11r
Correct answer: 802.11w
IEEE 802.11w (Protected Management Frames) added cryptographic protection for management frames, preventing spoofed deauthentication attacks.
Question 6: A qualitative risk assessment uses a 5×5 risk matrix. A threat is rated 4 (likelihood) and 3 (impact). A second threat is rated 3 (likelihood) and 5 (impact). Which should be remediated first?
- The first threat, because it has higher likelihood
- The second threat, because it has higher impact
- Both have equal priority since 4×3=12 and 3×5=15... the second threat (Correct answer)
- They are equivalent in risk score
Correct answer: Both have equal priority since 4×3=12 and 3×5=15... the second threat
Multiplying likelihood × impact: Threat 1 = 12, Threat 2 = 15, so the second threat has a higher overall risk score and should be prioritized.
Question 7: An organization transfers wireless security risk by requiring a third-party MSP to manage their wireless infrastructure under contract. Which element makes this risk transfer legally enforceable?
- A signed acceptable use policy
- A service level agreement (SLA) with defined liability clauses (Correct answer)
- An 802.1X implementation on all APs
- A completed vulnerability scan report
Correct answer: A service level agreement (SLA) with defined liability clauses
An SLA with defined liability, indemnification, and remediation clauses is the contractual mechanism that makes risk transference to a third party enforceable.
During a risk analysis, an organization determines its wireless infrastructure has an Asset Value of $200,000 and an Exposure Factor of 40% for a flood threat.
What is the SLE?