The role of a wireless penetration tester consists of various tasks. These tasks include following specific guidelines and adhering to the rules of engagement. What is the final step in the penetration testing process?
A. Verify the secure RF coverage area
B. Attempt social engineering attacks
C. Document and report findings
D. Remove deprecated technology
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
In order to acquire credentials of a valid user on a public hot-spot network, what attacks may be conducted? Choose the single completely correct answer.
A. Code injection and/or XSS
B. RF DoS and/or physical theft
C. Social engineering and/or eavesdropping
D. Authentication cracking and/or RF DoS
E. MAC denial of service and/or physical theft
正解:C
質問 3:
What security benefits are provided by endpoint security solution software? (Choose 3)
A. Can prevent connections to networks with security settings that do not conform to company policy
B. Can restrict client connections to networks with specific SSIDs and encryption types
C. Can be used to monitor for and prevent network attacks by nearby rogue clients or APs
D. Can collect statistics about a user's network use and monitor network threats while they are connected
正解:A,B,D
質問 4:
At what stage of the wireless client connection process does the station indicate its intention to use IEEE 802.11r fast transition procedures?
A. After the IEEE 802.11 standard authentication procedure
B. During the first attempt to access data after the initial IEEE 802.11 association
C. During the first association or reassociation within a mobility domain
D. After the station receives the mobility domain identifier (MDID) announced in the beacon
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Which of the following security attacks cannot be detected by a WIPS solution of any kind?
(Choose 2)
A. Rogue APs
B. Eavesdropping
C. Social engineering
D. DoS
正解:B,C
質問 6:
What standard WLAN client device behavior can be exploited by an attacker during a hijacking attack?
A. As specified by the Wi-Fi Alliance, clients using Open System authentication must allow direct client-to-client connections, even in an infrastructure BSS.
B. After the initial association and 4-way handshake, client stations and access points do not need to perform another 4-way handshake, even if connectivity is lost.
C. When the RF signal between a client and an access point is disrupted, the client device will attempt to associate to an access point with better signal quality.
D. Client drivers scan for and connect to access points in the 2.4 GHz band before scanning the 5 GHz band.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
1502 お客様のコメント





Kakimi -
出題確率の高い項目を重点的に解説した合格のためのCWSP-208攻略本です。隙間時間にも学習が進められます。