Security Protocols & Network Optimization Flashcards
7 cards from real CWT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Protocols & Network Optimization flashcards as text
What encryption algorithm does WPA3-Personal use to replace the Pre-Shared Key (PSK) handshake?
Answer: Simultaneous Authentication of Equals (SAE)
WPA3-Personal replaces PSK with SAE (Dragonfly handshake), providing forward secrecy and resistance to offline dictionary attacks.
Which EAP method uses server-side certificates only, with client credentials tunneled inside a TLS session?
Answer: PEAP
PEAP establishes a TLS tunnel using only a server certificate, then authenticates the client via MSCHAPv2 or another inner method inside the tunnel.
A wireless survey shows high co-channel interference on channel 6. Which optimization technique directly addresses this?
Answer: Reducing transmit power on overlapping APs
Lowering transmit power reduces the RF footprint of each AP, shrinking the co-channel interference zone.
Which 802.11 feature allows a client to roam between APs without re-running a full 802.1X authentication?
Answer: 802.11r (Fast BSS Transition)
802.11r pre-negotiates key material between APs, enabling a client to reassociate with a new AP in as few as two frames.
A deauthentication flood attack is possible against WPA2 networks because management frames are unprotected. Which amendment addresses this vulnerability?
Answer: 802.11w
802.11w (Protected Management Frames) cryptographically protects action, disassociation, and deauthentication frames.
In a WPA2-Enterprise deployment, what is the primary role of the PMK (Pairwise Master Key)?
Answer: It seeds the 4-Way Handshake to derive the PTK used for data encryption
The PMK is derived from 802.1X authentication and serves as the input to the 4-Way Handshake, which produces the PTK for frame encryption.
A CWT candidate is asked about the CSMA/CA mechanism. What does the 'CA' stand for and why is it used in Wi-Fi instead of collision detection?
Answer: Collision Avoidance; wireless nodes cannot detect collisions while transmitting
Wi-Fi uses collision avoidance because a transmitting node cannot simultaneously listen for collisions on the half-duplex wireless medium.