CWSP-207 Certified Wireless Security Professional (CWSP) Practice Questions
Prepare for CWSP-207 with more than an answer.
Unlock the full exam and previous versions
- v1Certified Wireless Security Professional (CWSP) 230 questions Current
- CWSP-206Legacy Certified Wireless Security Professional (CWSP) 54 questions Locked
- Exam fee
- $349.99 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 4
- Security Policy10%
- Vulnerabilities, Threats, and Attacks30%
- WLAN Security Design and Architecture50%
- Security Lifecycle Management10%
- 1
An attacker uses a tool to rapidly send forged Association Request frames to an access point from thousands of fictitious MAC addresses. The AP's client table fills up, and it begins rejecting connection attempts from legitimate users. What is the name of this Layer 2 Denial of Service attack?
Show answer details
Correct answer: C
This attack is known as an Association Flood. It is a Layer 2 Denial of Service (DoS) attack that targets the resources of an access point by overwhelming it with forged Association Request frames. By exhausting the AP's client association table, it prevents legitimate clients from connecting. RF Jamming is a Layer 1 attack. A Deauthentication Flood targets connected clients, not the AP's association table. An ARP spoofing attack is a man-in-the-middle attack.
- 2
A company is implementing a BYOD policy and wants to ensure that only devices with up-to-date antivirus software and the latest OS patches can connect to the corporate WLAN. The solution should automatically quarantine devices that fail the compliance check. Which technology is best suited to enforce this policy?
Show answer details
Correct answer: B
Network Access Control (NAC) is the technology designed for this purpose. A NAC solution performs 'posture assessment' on devices attempting to connect to the network. It checks for compliance with security policies, such as having a specific OS patch level, antivirus definitions, or firewall status. If a device is non-compliant, the NAC solution can place it into a quarantined VLAN for remediation. While MDM is used to manage the device and can push policies, NAC is the gatekeeper that enforces access based on the device's health state.
- 3
True or False: The 4-way handshake, used to generate and install encryption keys, occurs before the client station successfully completes the 802.11 association process with the access point.
Show answer details
Correct answer: B
This statement is false. The 802.11 connection process follows a specific order. The client must first successfully authenticate (Open System or, in the case of 802.1X, complete the EAP exchange) and then associate with the access point. Only after a successful association does the 4-way handshake begin to derive and install the temporal keys (PTK and GTK) used for encrypting data frames.
- 4
A security auditor is performing a manual review of an enterprise WLAN configuration. The auditor notes that the corporate SSID is configured to use TKIP/RC4 as its only encryption method. What is the primary reason this configuration is considered a major security vulnerability?
Show answer details
Correct answer: B
TKIP was designed as a transitional protocol to fix the flaws in WEP without requiring new hardware. However, it is based on the same underlying RC4 stream cipher as WEP. Over time, significant cryptographic weaknesses were discovered in RC4 that could be exploited to decrypt traffic or inject malicious packets. For this reason, the Wi-Fi Alliance has deprecated TKIP, and the 802.11 standard mandates that CCMP/AES be used for robust security. While the data rate limitation is a side effect, the core issue is the fundamental cryptographic weakness.
- 5
An administrator is reviewing the security logs of an access point and finds the following entry:
Dec 10 14:32:01 AP01 kernel: michael_mic_failure: packet dropped (src=AA:BB:CC:11:22:33)This message repeats several times within a 60-second window, after which the AP deauthenticates all connected clients and stops transmitting for one minute. What does this behavior indicate?
Show answer details
Correct answer: D
The log message
michael_mic_failureis specific to the TKIP encryption protocol. The Message Integrity Code (MIC), codenamed Michael, is used to protect against packet forgery. If an AP receives a frame with an invalid MIC, it logs a failure. As a countermeasure against active attacks, if two MIC failures are detected within 60 seconds, the AP will shut down the BSS for 60 seconds, deauthenticating all clients. This behavior indicates a potential attack on the network. - 6
A financial services company is deploying a new 802.11ax network and must comply with PCI-DSS 4.0 requirements. The security architect is designing the authentication mechanism for corporate-owned laptops. The primary requirements are to use device-specific credentials, prevent credential sharing, and ensure the strongest possible cryptographic protection. Which authentication and EAP method combination should be implemented to meet these requirements?
Show answer details
Correct answer: C
WPA3-Enterprise with EAP-TLS is the strongest combination. EAP-TLS uses client-side and server-side certificates for mutual authentication, providing device-specific credentials that cannot be easily shared. This meets the stringent requirements of PCI-DSS. WPA3-Personal uses a shared key, which violates the device-specific credential requirement. EAP-PEAP uses a server-side certificate but relies on username/password credentials inside the tunnel, which are weaker than certificates. OWE is designed for unauthenticated encryption on open networks, not for corporate authentication.
- 7
During a security audit of a university campus WLAN, a penetration tester successfully executes an attack by spoofing Disassociation frames targeting a lecturer's laptop, causing it to disconnect from the network during a presentation. The network is currently using WPA2-Enterprise with CCMP/AES. Which 802.11 amendment must be enabled to mitigate this specific attack?
Show answer details
Correct answer: C
The 802.11w amendment introduces Protected Management Frames (PMF), also known as Management Frame Protection (MFP). This feature cryptographically protects certain management frames, including Disassociation and Deauthentication frames, preventing attackers from spoofing them to launch denial-of-service attacks. 802.11r is for fast roaming, 802.11k provides radio measurement information, and 802.11e provides Quality of Service (QoS).
- 8
A security administrator is analyzing a packet capture of a failed WPA3-SAE connection attempt. The capture shows the client and AP exchanging several Authentication frames (Commit and Confirm), but the process fails and no Association occurs. What is the most likely cause of this failure?
Show answer details
Correct answer: C
The WPA3-SAE (Simultaneous Authentication of Equals) handshake, also known as the Dragonfly handshake, relies on both the client and the AP knowing the same pre-shared key (password). The Commit and Confirm frames are part of a key exchange process that will only succeed if both parties start with the same password. A mismatch will cause the cryptographic checks within the handshake to fail, preventing the establishment of a Pairwise Master Key (PMK) and subsequent association. SAE does not use certificates or a RADIUS server.
- 9
A hospital is developing its WLAN security policy to comply with HIPAA. The policy must address the security of patient data (ePHI) accessed via wireless devices. Which of the following policy statements are essential to include for HIPAA compliance? (Select TWO)
Show answer details
Correct answer: A, C
- 10
A consultant is performing a risk assessment for a retail company's guest WLAN. The company has identified that a compromise of the guest network leading to a pivot into the corporate network could result in a loss of $500,000 in data and remediation costs. Based on historical data and industry trends, such an event is estimated to occur once every ten years. What is the Annualized Loss Expectancy (ALE) for this specific risk?
Show answer details
Correct answer: B
The Annualized Loss Expectancy (ALE) is calculated by multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO). In this scenario, the SLE is $500,000. The ARO is the frequency of the event per year, which is once every ten years, or 1/10 = 0.1. Therefore, ALE = SLE * ARO = $500,000 * 0.1 = $50,000.
