Wireless Intrusion Prevention Systems (WIPS) provide what network security services? (Choose 2)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
B, E
Q: 2
Given: When the CCMP cipher suite is used for protection of data frames, 16 bytes of overhead are
added to the Layer 2 frame. 8 of these bytes comprise the MIC.
What purpose does the encrypted MIC play in protecting the data frame?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
B
Q: 3
Given: ABC Hospital wishes to create a strong security policy as a first step in securing their 802.11
WLAN.
Before creating the WLAN security policy, what should you ensure you possess?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
B
Q: 4
When implementing a WPA2-Enterprise security solution, what protocol must the selected RADIUS
server support?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
C
Q: 5
Given: XYZ Company has recently installed an 802.11ac WLAN. The company needs the ability to
control access to network services, such as file shares, intranet web servers, and Internet access
based on an employee's job responsibilities.
What WLAN security solution meets this requirement?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
D
Q: 6
You are configuring seven APs to prevent common security attacks. The APs are to be installed in a
small business and to reduce costs, the company decided to install all consumer-grade wireless
routers. The wireless routers will connect to a switch, which connects directly to the Internet
connection providing 50 Mbps of Internet bandwidth that will be shared among 53 wireless clients
and 17 wired clients.
To ensure the wireless network is as secure as possible from common attacks, what security measure
can you implement given only the hardware referenced?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
D
Q: 7
Given: You are using a Wireless Aggregator utility to combine multiple packet captures. One capture
exists for each of channels 1, 6 and 11. What kind of troubleshooting are you likely performing with
such a tool?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
C
Q: 8
Given: ABC Company secures their network with WPA2-Personal authentication and AES-CCMP
encryption.
What part of the 802.11 frame is always protected from eavesdroppers by this type of security?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
A
Q: 9
In order to acquire credentials of a valid user on a public hot-spot network, what attacks may be conducted? Choose the single completely correct answer
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
A
Q: 10
Given: You manage a wireless network that services 200 wireless users. Your facility requires 20
access points, and you have installed an IEEE 802.11-compliant implementation of 802.1X/LEAP with
AES-CCMP as an authentication and encryption solution.
In this configuration, the wireless network is initially susceptible to what type of attacks? (Choose 2)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
B, F
Q: 11
Given: ABC Corporation’s 802.11 WLAN is comprised of a redundant WLAN controller pair (N+1) and
30 access points implemented in 2004. ABC implemented WEP encryption with IPSec VPN
technology to secure their wireless communication because it was the strongest security solution
available at the time it was implemented. IT management has decided to upgrade the WLAN
infrastructure and implement Voice over Wi-Fi and is concerned with security because most Voice
over Wi-Fi phones do not support IPSec.
As the wireless network administrator, what new security solution would be best for protecting
ABC’s data?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
B
Q: 12
In what deployment scenarios would it be desirable to enable peer-to-peer traffic blocking?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
B
Q: 13
When used as part of a WLAN authentication solution, what is the role of LDAP?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
A
Q: 14
Given: Your network includes a controller-based WLAN architecture with centralized data forwarding.
The AP builds an encrypted tunnel to the WLAN controller. The WLAN controller is uplinked to the
network via a trunked 1 Gbps Ethernet port supporting all necessary VLANs for management,
control, and client traffic.
What processes can be used to force an authenticated WLAN client's data traffic into a specific VLAN
as it exits the WLAN controller interface onto the wired uplink? (Choose 3)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
B, C, D
Q: 15
Which one of the following is a valid reason to avoid the use of EAP-MD5 in production WLANs?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
C
Q: 16
What policy would help mitigate the impact of peer-to-peer attacks against wireless-enabled
corporate laptop computers when the laptops are also used on public access networks such as
wireless hot-spots?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
C
Topic 3, WLAN Security Design and Architecture
Q: 17
What statement accurately describes the functionality of the IEEE 802.1X standard?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
A
Q: 18
Given: An 802.1X/EAP implementation includes an Active Directory domain controller running
Windows Server 2012 and an AP from a major vendor. A Linux server is running RADIUS and it
queries the domain controller for user credentials. A Windows client is accessing the network.
What device functions as the EAP Supplicant?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
B
Q: 19
Given: A WLAN protocol analyzer trace reveals the following sequence of frames (excluding the ACK
frames):
1) 802.11 Probe Req and 802.11 Probe Rsp
2) 802.11 Auth and then another 802.11 Auth
3) 802.11 Assoc Req and 802.11 Assoc Rsp
4) EAPOL-KEY
5) EAPOL-KEY
6) EAPOL-KEY
7) EAPOL-KEY
What security mechanism is being used on the WLAN?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Correct Answer:
B
Q: 20
Given: Your company has just completed installation of an IEEE 802.11 WLAN controller with 20
controller-based APs. The CSO has specified PEAPv0/EAP-MSCHAPv2 as the only authorized WLAN
authentication mechanism. Since an LDAP-compliant user database was already in use, a RADIUS
server was installed and is querying authentication requests to the LDAP server.
Where must the X.509 server certificate and private key be installed in this network?