CWNA Risk Assessment & Management 4 — Questions and Answers
Question 1: A security team performs a wireless vulnerability scan and finds that several APs still support TKIP. Why does TKIP represent a security risk in modern wireless networks?
- TKIP requires a RADIUS server and is difficult to configure
- TKIP is vulnerable to known cryptographic weaknesses including the Beck-Tews attack (Correct answer)
- TKIP only supports 40-bit encryption keys
- TKIP cannot interoperate with WPA2-certified devices
Correct answer: TKIP is vulnerable to known cryptographic weaknesses including the Beck-Tews attack
TKIP was found vulnerable to the Beck-Tews and Ohigashi-Morii attacks, which can decrypt and inject short packets, making it insecure compared to AES-CCMP.
Question 2: During a wireless risk assessment, what does the term 'threat vector' specifically describe?
- The direction of RF signal propagation from an antenna
- The path or method an attacker uses to gain unauthorized access (Correct answer)
- The mathematical calculation used to determine risk scores
- The distance at which a wireless signal poses a risk
Correct answer: The path or method an attacker uses to gain unauthorized access
A threat vector is the specific path or mechanism through which a threat actor can exploit a vulnerability to cause harm to an asset.
Question 3: A WIPS alert fires when a station associates with an AP outside the approved vendor OUI list. This is an example of which security approach?
- Vulnerability scanning
- Anomaly-based detection (Correct answer)
- Signature-based detection
- Passive reconnaissance
Correct answer: Anomaly-based detection
Anomaly-based detection identifies deviations from a defined baseline (like approved OUI lists), flagging behavior that differs from the norm rather than matching known attack signatures.
Question 4: A hospital wireless network handles PHI (Protected Health Information). Which regulation most directly governs risk assessment requirements for this wireless infrastructure?
- PCI DSS
- SOX
- HIPAA Security Rule (Correct answer)
- GDPR
Correct answer: HIPAA Security Rule
The HIPAA Security Rule (45 CFR § 164.308) explicitly requires covered entities to conduct an accurate and thorough assessment of potential risks to the confidentiality, integrity, and availability of ePHI.
Question 5: An attacker sets up a high-power AP with the same SSID as the corporate network to lure clients. From a risk framework perspective, this is classified as which type of threat?
- Passive eavesdropping
- Social engineering
- Man-in-the-middle via evil twin AP (Correct answer)
- Denial of service
Correct answer: Man-in-the-middle via evil twin AP
An evil twin attack uses a rogue AP with a legitimate-appearing SSID to intercept traffic, placing the attacker in the middle of communications between the client and the real network.
Question 6: Which component of a wireless risk assessment specifically examines whether the organization's controls are functioning as intended?
- Threat identification
- Vulnerability scanning
- Control effectiveness testing (Correct answer)
- Asset valuation
Correct answer: Control effectiveness testing
Control effectiveness testing validates that implemented security controls (like WIPS, 802.1X, or encryption) are actually working as designed and providing the expected level of protection.
Question 7: A company calculates its ALE for a wireless DoS attack risk at $50,000/year. A mitigation solution costs $15,000/year. What is the value of this mitigation investment?
- The investment is not cost-effective since it doesn't eliminate the risk
- $35,000 net benefit per year, making it cost-effective (Correct answer)
- $15,000, equal to its annual cost
- $50,000, equal to the full ALE
Correct answer: $35,000 net benefit per year, making it cost-effective
Cost-benefit analysis: $50,000 ALE - $15,000 control cost = $35,000 net annual benefit, demonstrating the control is cost-effective.
A security team performs a wireless vulnerability scan and finds that several APs still support TKIP.
Why does TKIP represent a security risk in modern wireless networks?