CWNA Risk Assessment & Management 5 — Questions and Answers
Question 1: Which NIST publication provides a framework specifically for information security risk management that is commonly referenced in wireless security risk assessments?
- NIST SP 800-11
- NIST SP 800-30 (Correct answer)
- NIST SP 800-53
- NIST SP 800-63
Correct answer: NIST SP 800-30
NIST SP 800-30 'Guide for Conducting Risk Assessments' provides the foundational process for identifying, analyzing, and responding to information security risks.
Question 2: During a post-incident review, the security team finds that an attacker used a Karma attack to compromise a remote employee's device. What makes Karma attacks particularly effective?
- Karma attacks bypass WPA3 encryption completely
- Karma attacks respond to any probe request, impersonating any SSID a client searches for (Correct answer)
- Karma attacks require physical access to the target device
- Karma attacks exploit a flaw in the 802.11 authentication handshake
Correct answer: Karma attacks respond to any probe request, impersonating any SSID a client searches for
In a Karma attack, a rogue AP responds to all probe requests from clients looking for previously connected networks, tricking devices into auto-connecting to the attacker's AP.
Question 3: An organization uses a risk scoring system where likelihood and impact are each rated 1-5. A newly discovered wireless vulnerability scores 5/5 on impact but 1/5 on likelihood. How should this risk be documented?
- Immediately escalated as highest priority due to critical impact
- Scored as risk level 5 (5×1) and tracked in the risk register with periodic review (Correct answer)
- Dismissed because the low likelihood makes it negligible
- Treated as a risk transference candidate only
Correct answer: Scored as risk level 5 (5×1) and tracked in the risk register with periodic review
A 5×1 = 5 risk score should be documented in the risk register with appropriate oversight; the low likelihood doesn't eliminate the need to track and periodically reassess the risk.
Question 4: A wireless network assessment identifies that clients are using outdated EAP-MD5 for 802.1X authentication. What is the primary security risk of EAP-MD5?
- EAP-MD5 requires client certificates that expire frequently
- EAP-MD5 does not provide mutual authentication and is vulnerable to offline dictionary attacks (Correct answer)
- EAP-MD5 is incompatible with modern APs running 802.11ac or later
- EAP-MD5 increases wireless latency due to its complex handshake
Correct answer: EAP-MD5 does not provide mutual authentication and is vulnerable to offline dictionary attacks
EAP-MD5 only authenticates the client (not the server), making it vulnerable to man-in-the-middle attacks, and its MD5-hashed credentials are susceptible to offline dictionary and brute-force attacks.
Question 5: A risk assessment identifies that RF signals from a corporate WLAN extend 200 feet beyond the building perimeter. What is the most appropriate initial risk mitigation?
- Disabling the wireless network during non-business hours
- Adjusting transmit power and antenna placement to minimize signal leakage (Correct answer)
- Deploying WPA3 to secure the extended signal
- Installing a Faraday cage around the entire building
Correct answer: Adjusting transmit power and antenna placement to minimize signal leakage
Reducing transmit power and optimizing antenna placement is the most practical and direct mitigation to minimize RF signal spillage beyond the intended coverage area.
Question 6: A CWNA professional is reviewing the residual risk after deploying 802.1X/EAP-TLS on all corporate APs. Residual risk is best defined as:
- The total risk before any controls are applied
- The risk that remains after all selected controls have been implemented (Correct answer)
- The risk transferred to a third party through cyber insurance
- The risk identified but not yet assigned an owner
Correct answer: The risk that remains after all selected controls have been implemented
Residual risk is the remaining level of risk after controls have been applied; even with strong controls like EAP-TLS, some risk (e.g., compromised certificates) always remains.
Question 7: An enterprise discovers that a contractor installed an unauthorized AP to extend coverage in a remote office. Which risk management process failure does this primarily indicate?
- Inadequate disaster recovery planning
- Failure in change management and access control processes (Correct answer)
- Insufficient wireless intrusion prevention system tuning
- Incomplete asset valuation methodology
Correct answer: Failure in change management and access control processes
An unauthorized AP installation indicates a failure in change management controls (no approval process) and physical/logical access controls (contractor had physical network access).
Which NIST publication provides a framework specifically for information security risk management that is commonly referenced in wireless security risk assessments?