Wireless Security & Troubleshooting Techniques Flashcards
7 cards from real CWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Wireless Security & Troubleshooting Techniques flashcards as text
A network admin notices clients frequently deauthenticating from the WLAN. Which tool would BEST help identify whether a deauthentication attack is occurring?
Answer: Wireless protocol analyzer (packet capture)
A wireless protocol analyzer can capture 802.11 management frames and reveal illegitimate deauthentication frames from a rogue source.
Which 802.11 frame type is exploited in a deauthentication flood attack?
Answer: Management frames
Deauthentication packets are 802.11 management frames, and because they were historically unprotected, attackers can spoof them to disconnect clients.
PMF (Protected Management Frames) as defined in 802.11w primarily defends against which attack vector?
Answer: Spoofed deauthentication/disassociation frames
802.11w cryptographically protects unicast and broadcast management frames, preventing an attacker from forging deauth/disassoc packets.
A user in a warehouse reports intermittent drops every ~20 minutes. The admin finds the AP association log shows the client reassociating repeatedly. What is the MOST likely cause?
Answer: Client roaming aggressiveness set too low causing sticky client behavior
A sticky client holds onto a distant AP instead of roaming to a closer one, causing signal degradation and eventual disconnection, then reconnection.
Which EAP method uses a server-side certificate and a client-side certificate (mutual TLS) for authentication?
Answer: EAP-TLS
EAP-TLS requires both the RADIUS server and the supplicant to present X.509 certificates, providing mutual authentication.
An 802.1X-secured WLAN is failing to authenticate users. The RADIUS server log shows 'unknown CA.' What is the MOST likely fix?
Answer: Install the correct CA certificate in the supplicant's trust store
The 'unknown CA' error means the client does not trust the certificate authority that signed the RADIUS server's certificate; adding the CA cert to the client resolves this.
A CWS technician is performing a site survey and discovers an SSID broadcasting the same name as the corporate network but with a stronger signal. This is BEST described as:
Answer: An evil twin AP
An evil twin AP mimics a legitimate SSID with higher power to lure clients into connecting to a rogue access point.