Free CWSP-208 Practice Test Questions and Answers (2026) | Cert Empire Practice Questions
Free preview: 20 questions.
CWNP CWSP 208
Q: 1
Given: ABC Company is implementing a secure 802.11 WLAN at their headquarters (HQ) building in
New York and at each of the 10 small, remote branch offices around the United States. 802.1X/EAP is
ABC’s preferred security solution, where possible. All access points (at the HQ building and all branch
offices) connect to a single WLAN controller located at HQ. Each branch office has only a single AP
and minimal IT resources.
What security best practices should be followed in this deployment scenario?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
You must support a TSN as you have older wireless equipment that will not support the required
processing of AES encryption. Which one of the following technologies will you use on the network
so that a TSN can be implemented that would not be required in a network compliant with 802.11-
2012 non-deprecated technologies?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
Given: The Marketing department’s WLAN users need to reach their file and email server as well as
the Internet, but should not have access to any other network resources.
What single WLAN security feature should be implemented to comply with these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
What policy would help mitigate the impact of peer-to-peer attacks against wireless-enabled
corporate laptop computers when the laptops are also used on public access networks such as
wireless hot-spots?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
Given: ABC Hospital wishes to create a strong security policy as a first step in securing their 802.11
WLAN.
Before creating the WLAN security policy, what should you ensure you possess?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
Select the answer option that arranges the numbered events in the correct time sequence (first to
last) for a client associating to a BSS using EAP-PEAPv0/MSCHAPv2.
1. Installation of PTK
2. Initiation of 4-way handshake
3. Open system authentication
4. 802.11 association
5. 802.1X controlled port is opened for data traffic
6. Client validates server certificate
7. AS validates client credentials
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
Given: John Smith uses a coffee shop's Internet hot-spot (no authentication or encryption) to transfer
funds between his checking and savings accounts at his bank's website. The bank’s website uses the
HTTPS protocol to protect sensitive account information. While John was using the hot-spot, a hacker
was able to obtain John’s bank account user ID and password and exploit this information.
What likely scenario could have allowed the hacker to obtain John’s bank account user ID and
password?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
What are the three roles of the 802.1X framework, as defined by the 802.1X standard, that are performed by the client STA, the AP (or WLAN controller), and the RADIUS server? (Choose 3)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
What TKIP feature was introduced to counter the weak integrity check algorithm used in WEP?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
Given: ABC Company has recently installed a WLAN controller and configured it to support WPA2-
Enterprise security. The administrator has configured a security profile on the WLAN controller for
each group within the company (Marketing, Sales, and Engineering).
How are authenticated users assigned to groups so that they receive the correct security profile
within the WLAN controller?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
Given: When the CCMP cipher suite is used for protection of data frames, 16 bytes of overhead are
added to the Layer 2 frame. 8 of these bytes comprise the MIC.
What purpose does the encrypted MIC play in protecting the data frame?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
Given: XYZ Company has recently installed a controller-based WLAN and is using a RADIUS server to
query authentication requests to an LDAP server. XYZ maintains user-based access policies and would
like to use the RADIUS server to facilitate network authorization.
What RADIUS features could be used by XYZ to assign the proper network permissions to users
during authentication? (Choose 2)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
Given: ABC Company has a WLAN controller using WPA2-Enterprise with PEAPv0/MS-CHAPv2 and AES-CCMP to secure their corporate wireless dat a. They wish to implement a guest WLAN for guest users to have Internet access, but want to implement some security controls. The security requirements for the hot-spot include: Cannot access corporate network resources Network permissions are limited to Internet access All stations must be authenticated What security controls would you suggest? (Choose the single best answer)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
The IEEE 802.11 standard defined Open System authentication as consisting of two auth frames and
two assoc frames. In a WPA2-Enterprise network, what process immediately follows the 802.11
association procedure?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
You have been recently hired as the wireless network administrator for an organization spread across
seven locations. They have deployed more than 100 APs, but they have not been managed in either
an automated or manual process for more than 18 months. Given this length of time, what is one of
the first things you should evaluate from a security perspective?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
What protocols allow a network administrator to securely manage the configuration of WLAN
controllers and access points? (Choose 2)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
Given: You are the WLAN administrator in your organization and you are required to monitor the
network and ensure all active WLANs are providing RSNs. You have a laptop protocol analyzer
configured.
In what frame could you see the existence or non-existence of proper RSN configuration parameters
for each BSS through the RSN IE?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
Given: Your company has just completed installation of an IEEE 802.11 WLAN controller with 20
controller-based APs. The CSO has specified PEAPv0/EAP-MSCHAPv2 as the only authorized WLAN
authentication mechanism. Since an LDAP-compliant user database was already in use, a RADIUS
server was installed and is querying authentication requests to the LDAP server.
Where must the X.509 server certificate and private key be installed in this network?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
Given: ABC Company is an Internet Service Provider with thousands of customers. ABC’s customers
are given login credentials for network access when they become a customer. ABC uses an LDAP
server as the central user credential database. ABC is extending their service to existing customers in
some public access areas and would like to use their existing database for authentication.
How can ABC Company use their existing user database for wireless user authentication as they
implement a large-scale WPA2-Enterprise WLAN security solution?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
Given: ABC Corporation’s 802.11 WLAN is comprised of a redundant WLAN controller pair (N+1) and
30 access points implemented in 2004. ABC implemented WEP encryption with IPSec VPN
technology to secure their wireless communication because it was the strongest security solution
available at the time it was implemented. IT management has decided to upgrade the WLAN
infrastructure and implement Voice over Wi-Fi and is concerned with security because most Voice
over Wi-Fi phones do not support IPSec.
As the wireless network administrator, what new security solution would be best for protecting
ABC’s data?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20