โ† All CWS Flashcard Decks

Risk Assessment & Mitigation Flashcards

7 cards from real CWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Mitigation flashcards as text
  1. A company discovers its Wi-Fi network is vulnerable to a KRACK attack. Which layer of the OSI model is primarily targeted by this exploit?

    Answer: Data Link layer

    KRACK (Key Reinstallation Attack) targets the 4-way handshake process at the Data Link layer (Layer 2) of the OSI model, specifically the WPA2 protocol.

  2. During a wireless risk assessment, an analyst identifies multiple APs broadcasting SSIDs with default manufacturer names. What is the primary risk this represents?

    Answer: Attackers can easily identify the hardware vendor and exploit known default credentials

    Default SSIDs reveal the hardware manufacturer, allowing attackers to look up default credentials and known vulnerabilities for that specific device.

  3. Which mitigation technique is MOST effective against a rogue AP that is mimicking a legitimate corporate SSID?

    Answer: Implementing 802.1X authentication with mutual certificate verification

    802.1X with mutual certificate verification requires both the client and server to authenticate each other, preventing clients from connecting to rogue APs that cannot present a valid certificate.

  4. A wireless penetration tester uses a tool to capture the PMKID from a WPA2 network without requiring any client to be connected. What type of attack does this enable?

    Answer: Offline dictionary/brute-force attack against the PSK

    The PMKID is derived from the PMK (which is based on the PSK), allowing an attacker to perform offline brute-force or dictionary attacks against the pre-shared key without needing a connected client.

  5. What is the purpose of a wireless honeypot in a risk mitigation strategy?

    Answer: To lure and detect attackers while gathering threat intelligence

    A wireless honeypot attracts attackers to a decoy network, allowing security teams to detect intrusion attempts and gather intelligence about attack methods and attacker behavior.

  6. In a risk assessment, the likelihood of a denial-of-service attack via 802.11 deauthentication frames is rated HIGH. Which control BEST mitigates this specific risk?

    Answer: Deploying WPA3 with Protected Management Frames (PMF)

    WPA3 mandates Protected Management Frames (PMF/802.11w), which cryptographically protects deauthentication and disassociation frames, preventing spoofed deauth attacks.

  7. A risk assessment reveals that an organization's wireless network lacks segmentation between IoT devices and corporate workstations. What is the MOST significant risk this creates?

    Answer: Lateral movement from a compromised IoT device to sensitive corporate systems

    Without network segmentation, a compromised IoT device can be used as a pivot point to laterally move and attack more sensitive corporate systems on the same network.