CWT Security Protocols & Network Optimization 2 — Questions and Answers
Question 1: Which 802.11 amendment introduced the Robust Security Network (RSN) framework?
- 802.11i (Correct answer)
- 802.11e
- 802.11n
- 802.11ac
Correct answer: 802.11i
802.11i defined the RSN framework, mandating CCMP/AES encryption and replacing the flawed WEP standard.
Question 2: A wireless technician needs to prevent rogue APs from associating with the corporate WLAN. Which feature should be enabled on the WLAN controller?
- Rogue AP containment (Correct answer)
- Band steering
- MU-MIMO
- DFS channel scanning
Correct answer: Rogue AP containment
Rogue AP containment actively de-authenticates clients that attempt to connect to unauthorized access points.
Question 3: What is the purpose of the 4-Way Handshake in WPA2?
- To derive and verify the Pairwise Transient Key (PTK) (Correct answer)
- To authenticate the RADIUS server
- To negotiate the SSID broadcast interval
- To assign an IP address to the client
Correct answer: To derive and verify the Pairwise Transient Key (PTK)
The 4-Way Handshake uses the PMK to mutually derive and confirm the PTK used for unicast frame encryption.
Question 4: Which QoS access category provides the highest priority for time-sensitive traffic like VoIP?
- AC_VO (Voice) (Correct answer)
- AC_VI (Video)
- AC_BE (Best Effort)
- AC_BK (Background)
Correct answer: AC_VO (Voice)
AC_VO has the shortest AIFSN and TXOP values, giving voice traffic the lowest contention window and fastest channel access.
Question 5: An enterprise WLAN uses 802.1X. A client presents credentials to the AP, which forwards them to an authentication server. What role does the AP play in this architecture?
- Authenticator (Correct answer)
- Supplicant
- Authentication Server
- RADIUS proxy
Correct answer: Authenticator
In 802.1X, the AP acts as the Authenticator, relaying EAP messages between the supplicant (client) and authentication server.
Question 6: Which attack exploits the WPS PIN authentication mechanism to gain unauthorized access to a WPA2 network?
- Pixie Dust / Brute-force WPS PIN attack (Correct answer)
- KRACK attack
- Deauthentication flood
- Evil Twin attack
Correct answer: Pixie Dust / Brute-force WPS PIN attack
The WPS PIN can be brute-forced in ~11,000 attempts due to its split-PIN design flaw; the Pixie Dust attack exploits weak nonce generation.
Question 7: A technician is optimizing channel reuse in a 2.4 GHz deployment. Which set of non-overlapping channels should be used?
- 1, 6, 11 (Correct answer)
- 1, 5, 9
- 2, 7, 12
- 1, 4, 8
Correct answer: 1, 6, 11
Channels 1, 6, and 11 are the only three non-overlapping 20 MHz channels in the 2.4 GHz band in North America.
Which 802.11 amendment introduced the Robust Security Network (RSN) framework?