Risk Assessment & Mitigation Flashcards
7 cards from real CWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Assessment & Mitigation flashcards as text
During a site survey, an analyst detects a wireless client probe-requesting an SSID named 'Free_Airport_WiFi' in a corporate office. What security concern does this indicate?
Answer: The client is vulnerable to an evil twin attack targeting that remembered network
Probe requests for remembered SSIDs allow nearby attackers to create a matching evil twin AP that the client may automatically connect to, bypassing user awareness.
Which of the following BEST describes the risk associated with using WPS PIN authentication on a wireless router?
Answer: WPS PIN is vulnerable to online brute-force due to a design flaw splitting the PIN into two halves
The WPS PIN has a design flaw where it is validated in two separate halves (4+3 digits), reducing the effective keyspace from 10^7 to about 11,000 combinations, making it trivially brute-forceable.
A risk assessment identifies that wireless clients in a hospital are using open (unencrypted) Wi-Fi to access the EHR system via HTTPS. Which residual risk remains even with HTTPS?
Answer: SSL stripping attacks can downgrade HTTPS connections if HSTS is not implemented
Without HSTS (HTTP Strict Transport Security), a man-in-the-middle attacker on the open network can perform SSL stripping to downgrade HTTPS connections to unencrypted HTTP.
What is the primary risk of using a shared PSK (pre-shared key) for a large number of employees on a corporate wireless network?
Answer: A single compromised employee exposes the entire network, and rekeying requires updating all devices
With a shared PSK, one compromised credential exposes the entire network, and rotating the key requires reconfiguring every device, making credential management operationally challenging.
An organization wants to assess the risk from nearby competing businesses' Wi-Fi networks. What specific threat should they evaluate?
Answer: Accidental client association to neighboring networks exposing corporate traffic
Accidental association occurs when corporate devices connect to similarly named or open neighboring networks, potentially exposing sensitive data to untrusted networks.
Which risk mitigation approach is MOST appropriate when wireless communication is required in an environment with significant RF interference and jamming threats?
Answer: Using frequency hopping spread spectrum (FHSS) or direct sequence spread spectrum (DSSS) techniques
FHSS and DSSS spread signals across multiple frequencies, making them resilient to narrow-band jamming and interference because they don't rely on a single channel.
A CWS candidate is reviewing a wireless risk register. An identified risk has a HIGH impact but VERY LOW likelihood. How should this risk typically be prioritized?
Answer: Accepted or monitored with contingency plans, as risk score may be medium
Risk prioritization uses both impact and likelihood; a high impact but very low likelihood risk typically results in a medium risk score, warranting monitoring and contingency planning rather than immediate maximum investment.