Wireless Network Security Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Wireless Network Security flashcards as text
Which tool from the aircrack-ng suite performs the final dictionary or brute-force attack against a captured WPA2 handshake file?
Answer: aircrack-ng
aircrack-ng reads captured .cap files and performs offline dictionary or brute-force attacks against the WPA2 PBKDF2-HMAC-SHA1 hash.
What command tests whether a wireless adapter supports packet injection, which is required for most wireless attacks?
Answer: aireplay-ng --test wlan0mon
aireplay-ng --test (or -9) sends test packets to verify the adapter can inject frames, a prerequisite for deauthentication and other active wireless attacks.
What is the Karma attack in the context of wireless penetration testing?
Answer: A rogue AP that responds to any probe request, impersonating previously seen networks to lure clients
The Karma attack exploits clients that auto-connect to known SSIDs by having the rogue AP respond positively to all probe requests, regardless of SSID.
Which Kali Linux tool provides an all-in-one framework for rogue AP creation, wireless MITM attacks, and traffic interception?
Answer: Bettercap
Bettercap is a comprehensive offensive framework supporting Wi-Fi attacks (rogue AP, deauth, MITM), ARP spoofing, and HTTP/HTTPS interception.
Which security feature introduced in WPA3 provides resistance to offline dictionary attacks and ensures forward secrecy?
Answer: Simultaneous Authentication of Equals (SAE)
WPA3 uses SAE (also called the Dragonfly handshake) which is resistant to offline dictionary attacks and provides forward secrecy by deriving unique session keys.
When aircrack-ng fails to crack a captured WPA2 handshake with a standard wordlist, what is the most effective next step?
Answer: Use hashcat with rule-based mangling against the converted hash file
Hashcat with rule files (e.g., best64.rule) applies transformations like capitalization and substitution to wordlist entries, dramatically expanding the effective keyspace.
What file extension does airodump-ng use when saving captured wireless packets with the -w (write) flag?
Answer: .cap
airodump-ng saves captured wireless frames in .cap format; it also generates companion .csv and .kismet.xml files with network metadata.