Step2Study
IT & Technology312-50100% Free

EC-Council Certified Ethical Hacker (CEH) v12

Practice bank
212 Qs
Real exam
125 Qs
Time limit
240 min
Passing
70%

Exam blueprint

Information Security and Ethical Hacking Overview
6%
Reconnaissance Techniques
21%
System Hacking Phases and Attack Techniques
17%
Web Application Hacking
16%
Wireless Network Hacking
6%
Mobile Platform, IoT, and OT Hacking
8%
Cloud Computing
6%
Cryptography
6%
Malware Threats
12%
Social Engineering
2%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 125 questions each · 240 min · pass 70% · 212 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

EC-Council Certified Ethical Hacker (CEH) v12 practice test questions

Sample questions from the 212-question bank, with answers and explanations.

All questions
  1. 1. A penetration tester is evaluating the security of a corporate wireless network. They have successfully captured a WPA2-Personal 4-way handshake using a tool like Airodump-ng. The target network's SSID is 'CorpNet' and its PSK is known to be a dictionary word followed by a year. Which of the following attack methods would be MOST efficient for attempting to recover the PSK in this scenario?

    Wireless Network Hacking

    • A. Rainbow table attack with precomputed hashes
    • B. Evil Twin attack to trick users into revealing the PSK
    • C. Brute-force attack with a custom character set
    • D. Dictionary attack using a targeted wordlist
    Show answer

    D. Dictionary attack using a targeted wordlist

    Since the PSK is known to follow a predictable pattern (dictionary word + year), a dictionary attack using a targeted wordlist combining common dictionary words and years would be the most efficient method to recover the PSK from the captured handshake.

  2. 2. A security analyst is investigating a suspected wireless intrusion. They have captured a large amount of raw 802.11 traffic in a .pcap file. To identify potential rogue access points, analyze beacon frames, and detect other anomalies, which specialized wireless analysis tool is specifically designed for passive sniffing and network discovery?

    Wireless Network Hacking

    • A. Nmap
    • B. Hping3
    • C. Netcat
    • D. Kismet
    Show answer

    D. Kismet

    Kismet is a wireless network detector, sniffer, and intrusion detection system. It operates in passive mode, collecting 802.11 frames to identify access points, clients, SSIDs, and detect various wireless anomalies and rogue devices, making it ideal for the described task.

  3. 3. A wireless network administrator is deploying a new WPA3-enabled network. They are considering the security implications of client compatibility. Which of the following WPA3 features provides protection against passive offline dictionary attacks, even if an attacker captures the initial handshake, and is a mandatory component for WPA3-Personal networks?

    Wireless Network Hacking

    • A. Opportunistic Wireless Encryption (OWE)
    • B. Enhanced Open security
    • C. Simultaneous Authentication of Equals (SAE)
    • D. 192-bit cryptographic strength
    Show answer

    C. Simultaneous Authentication of Equals (SAE)

    Simultaneous Authentication of Equals (SAE), also known as Dragonfly Key Exchange, is a mandatory component of WPA3-Personal. It provides a secure key establishment protocol that makes passive offline dictionary attacks ineffective by ensuring forward secrecy and resistance to side-channel attacks.

  4. 4. A security analyst is performing a site survey for a new wireless deployment and is concerned about potential interference from non-Wi-Fi devices. Which frequency band is most susceptible to interference from common household appliances like microwave ovens and cordless phones, requiring careful channel planning to avoid performance degradation?

    Wireless Network Hacking

    • A. 60 GHz band
    • B. 2.4 GHz band
    • C. 6 GHz band
    • D. 5 GHz band
    Show answer

    B. 2.4 GHz band

    The 2.4 GHz band is widely used by many non-Wi-Fi devices, including microwave ovens, cordless phones, and Bluetooth devices. These devices can cause significant interference, leading to poor Wi-Fi performance, making careful channel planning crucial in this band.

  5. 5. A security auditor is performing a penetration test against a client's wireless network. They notice that the network's APs are broadcasting multiple SSIDs, some of which are hidden. During a deauthentication attack against a connected client, the client reassociates with the network, and the auditor captures the full 4-way handshake. Which of the following tools is specifically designed to perform this type of targeted deauthentication and capture the handshake for WPA/WPA2 cracking?

    Wireless Network Hacking

    • A. Airmon-ng
    • B. Netcat
    • C. Aireplay-ng
    • D. Wireshark
    Show answer

    C. Aireplay-ng

    Aireplay-ng is a part of the Aircrack-ng suite specifically used for injecting frames, including deauthentication frames, to force clients to disconnect and reconnect, thereby capturing the WPA/WPA2 4-way handshake.

  6. 6. A security analyst is conducting a wireless assessment and discovers an access point broadcasting an SSID named 'FreeWiFi' with no encryption enabled. The analyst observes numerous clients connecting to this network. Which type of attack is most readily facilitated by this configuration, allowing an attacker to intercept client communications?

    Wireless Network Hacking

    • A. Evil Twin Attack
    • B. WPA2 Krack Attack
    • C. Deauthentication Attack
    • D. WPS Brute-Force Attack
    Show answer

    A. Evil Twin Attack

    An Evil Twin attack involves an attacker setting up a rogue AP with the same SSID as a legitimate network, often without encryption, to trick users into connecting and then intercepting their traffic.

  7. 7. A penetration tester is performing a wireless assessment and identifies several access points broadcasting the same SSID. They notice that clients frequently roam between these access points. To efficiently map the physical locations of these APs and their associated clients, and to understand the overall wireless network topology, which of the following tools is BEST suited for passive wireless reconnaissance and visualization?

    Wireless Network Hacking

    • A. Burp Suite
    • B. Metasploit Framework
    • C. Kismet
    • D. Nmap
    Show answer

    C. Kismet

    Kismet is a passive wireless network detector, sniffer, and intrusion detection system. It excels at discovering and mapping wireless networks (APs and clients), including hidden SSIDs, and can visualize the network topology, making it ideal for the described reconnaissance task.

  8. 8. A penetration tester is targeting a WPA2-Enterprise network that uses 802.1X for authentication. The tester successfully captures EAPOL frames between a client and the RADIUS server. To proceed with an offline attack against the captured credentials, which specific EAP method's inner tunnel credentials must the tester attempt to extract and crack?

    Wireless Network Hacking

    • A. EAP-TLS
    • B. EAP-MD5
    • C. LEAP
    • D. PEAP (MSCHAPv2)
    Show answer

    D. PEAP (MSCHAPv2)

    When PEAP is used with MSCHAPv2 as the inner authentication method, the MSCHAPv2 hashes are vulnerable to offline dictionary attacks if captured, as they can be extracted from the EAPOL frames. EAP-TLS and LEAP have different vulnerabilities or are not commonly cracked offline in this manner.

  9. 9. A security consultant is advising a client on securing their wireless infrastructure against denial-of-service (DoS) attacks. The client is particularly concerned about attacks that prevent legitimate users from associating with the access point or maintain existing connections. Which countermeasure directly addresses the vulnerability exploited by deauthentication and disassociation attacks?

    Wireless Network Hacking

    • A. Implementing strong WPA3 encryption
    • B. Enabling MAC address filtering
    • C. Deploying a wireless intrusion prevention system (WIPS)
    • D. Utilizing management frame protection (802.11w)
    Show answer

    D. Utilizing management frame protection (802.11w)

    Management Frame Protection (802.11w) specifically addresses the vulnerability of unauthenticated management frames, such as deauthentication and disassociation frames. It encrypts and adds integrity checks to these frames, preventing attackers from spoofing them to disconnect legitimate users.

  10. 10. A security auditor is performing a wireless penetration test on a corporate network. They successfully capture a WPA/WPA2 4-way handshake. To crack the passphrase offline, which specific cryptographic element from the handshake is essential for a dictionary or brute-force attack?

    Wireless Network Hacking

    • A. Initialization Vector (IV)
    • B. Message Integrity Code (MIC)
    • C. Pairwise Master Key (PMK)
    • D. Pairwise Transient Key (PTK)
    Show answer

    B. Message Integrity Code (MIC)

    The Message Integrity Code (MIC) in the 4-way handshake is crucial for offline cracking. An attacker can use a dictionary or brute-force attack to guess the passphrase, derive the PMK, PTK, and then calculate the MIC. If the calculated MIC matches the captured MIC, the guessed passphrase is correct.

  11. 11. A penetration tester is targeting a wireless network that utilizes WPS (Wi-Fi Protected Setup) for easy device connection. The tester uses a tool to systematically guess the WPS PIN. Which specific WPS attack exploits the design flaw where the PIN verification process can be broken into two smaller, independent halves, significantly reducing the number of attempts needed for a brute-force attack?

    Wireless Network Hacking

    • A. Pixie Dust Attack
    • B. Reaver Attack
    • C. Evil Twin Attack
    • D. ChopChop Attack
    Show answer

    B. Reaver Attack

    The Reaver attack (named after the tool that popularized it) exploits the design flaw in WPS where the AP reports the correctness of the first four digits of the PIN separately from the last three digits (and checksum). This allows an attacker to brute-force the PIN in two halves, drastically reducing the search space.

  12. 12. A security consultant is performing a wireless penetration test. They observe an access point (AP) that is configured to require clients to register their MAC addresses before being granted network access. The consultant spoofs the MAC address of an authorized client and successfully connects to the network. Which of the following wireless security mechanisms was circumvented by this action?

    Wireless Network Hacking

    • A. WPA2-Enterprise authentication
    • B. MAC address filtering
    • C. WPS (Wi-Fi Protected Setup)
    • D. SSID hiding
    Show answer

    B. MAC address filtering

    MAC address filtering attempts to restrict network access to devices with specific MAC addresses. By spoofing an authorized MAC address, the penetration tester directly bypassed this security mechanism, demonstrating its ineffectiveness as a primary security control.

  13. 13. A network architect is designing a wireless network for a critical infrastructure facility. The primary requirement is to ensure the integrity and authenticity of management frames to prevent denial-of-service attacks like deauthentication floods. Which IEEE 802.11 amendment specifically addresses this requirement by providing protection for management frames?

    Wireless Network Hacking

    • A. 802.11ac
    • B. 802.11i
    • C. 802.11ax
    • D. 802.11w
    Show answer

    D. 802.11w

    IEEE 802.11w, also known as Protected Management Frames (PMF), is an amendment that provides mechanisms to protect management frames from spoofing and tampering, thereby mitigating attacks like deauthentication and disassociation floods.

  14. 14. A security researcher discovers a new type of wireless attack where a malicious actor sends specially crafted control frames to a target access point, causing it to crash or operate erratically, disrupting service for all connected clients. This attack exploits a vulnerability in the AP's firmware handling of these specific frame types. Which category of wireless attacks does this scenario BEST describe?

    Wireless Network Hacking

    • A. Denial-of-Service (DoS) attack
    • B. Eavesdropping attack
    • C. Evil Twin attack
    • D. Man-in-the-Middle attack
    Show answer

    A. Denial-of-Service (DoS) attack

    The scenario describes an attack that disrupts the normal operation of the access point, leading to service disruption for connected clients. This directly aligns with the definition of a Denial-of-Service (DoS) attack, which aims to make a network resource unavailable to its legitimate users.

  15. 15. A cybersecurity analyst is tasked with performing a site survey for a new corporate wireless network in a multi-story building. The goal is to ensure optimal coverage and minimize interference. While using a spectrum analyzer, the analyst identifies significant interference in the 5 GHz band, specifically from devices operating on channels typically used by Wi-Fi. Which of the following is the MOST likely source of this interference?

    Wireless Network Hacking

    • A. Cordless phones
    • B. Microwave ovens
    • C. Bluetooth headphones
    • D. Radar systems
    Show answer

    D. Radar systems

    Radar systems, particularly weather radar and military radar, operate in the 5 GHz band and can cause significant interference with Wi-Fi networks using the same frequency range. They often utilize DFS channels.

  16. 16. An attacker is attempting to exploit a vulnerability in a WPA2-Personal network that uses a weak passphrase. They have captured a limited number of frames from the 4-way handshake. Instead of a full dictionary attack, they decide to use a precomputed rainbow table that maps common passphrases directly to their corresponding Pairwise Master Keys (PMKs). What is the primary limitation of using rainbow tables for cracking WPA2-Personal, especially compared to their effectiveness against other hash types?

    Wireless Network Hacking

    • A. The use of a salt (SSID) in WPA2-Personal makes generic rainbow tables impractical.
    • B. Rainbow tables are only effective against WEP, not WPA2.
    • C. The 4-way handshake nonce values change too frequently for rainbow tables to be useful.
    • D. WPA2-Personal uses AES encryption, which is resistant to rainbow table attacks.
    Show answer

    A. The use of a salt (SSID) in WPA2-Personal makes generic rainbow tables impractical.

    WPA2-Personal uses the SSID as a salt during the PBKDF2 derivation of the PMK. This means a unique PMK is generated for the same passphrase on different SSIDs. Generic rainbow tables, which precompute hashes without considering a dynamic salt, become impractical because a separate table would be needed for every possible SSID, making them prohibitively large.

  17. 17. A network security engineer is tasked with securing a wireless network that serves a public area, offering free Wi-Fi. The primary concern is protecting user privacy and preventing unauthorized access to client data, even if the network is open. Which security measure, when implemented on the access points, would provide individual encryption for each client session without requiring a pre-shared key or 802.1X authentication?

    Wireless Network Hacking

    • A. Enhanced Open (OWE)
    • B. WPA2-Enterprise with EAP-TLS
    • C. Captive Portal with HTTPS
    • D. WPA3-Personal with SAE
    Show answer

    A. Enhanced Open (OWE)

    Enhanced Open (OWE), as integrated into WPA3, provides opportunistic encryption for open Wi-Fi networks. It establishes a secure, individualized connection for each client without requiring a password or 802.1X, thus protecting traffic from passive sniffing while maintaining ease of access.

  18. 18. A penetration tester is analyzing a wireless network that uses WPA2-Enterprise with 802.1X authentication. During the reconnaissance phase, they observe that the network requires users to input their domain credentials. Which authentication protocol is most likely being used in conjunction with 802.1X for this scenario?

    Wireless Network Hacking

    • A. LEAP
    • B. WEP
    • C. PEAP
    • D. TKIP
    Show answer

    C. PEAP

    PEAP (Protected Extensible Authentication Protocol) is commonly used with WPA2-Enterprise and 802.1X to encapsulate EAP methods like MSCHAPv2 within a TLS tunnel, allowing secure transmission of credentials like usernames and passwords.

  19. 19. A wireless network is configured with WPA2-Enterprise using EAP-TLS. A penetration tester attempts to perform a Man-in-the-Middle (MitM) attack by setting up a rogue access point (Evil Twin) that mimics the legitimate network. The tester configures the rogue AP to request a username and password from connecting clients. However, legitimate clients, configured to use EAP-TLS, refuse to connect to the rogue AP and display a certificate warning. What specific security feature of EAP-TLS is preventing the success of this MitM attack?

    Wireless Network Hacking

    • A. Mutual authentication based on client and server certificates
    • B. Dynamic Frequency Selection (DFS) for channel management
    • C. Pre-Shared Key (PSK) requirement for connection
    • D. Use of Protected Management Frames (PMF)
    Show answer

    A. Mutual authentication based on client and server certificates

    EAP-TLS requires both the client and the server (RADIUS/authenticator) to present and validate digital certificates. When the rogue AP tries to impersonate the legitimate network, it cannot present a valid server certificate trusted by the client, leading to the client refusing connection and displaying a warning. This mutual certificate-based authentication prevents the MitM attack.

  20. 20. A penetration tester is attempting to compromise a WPA2-Personal network. They have captured the 4-way handshake and are now performing an offline dictionary attack. The target network uses a passphrase of 'SecurePassword123' and the SSID is 'MyCompanyWiFi'. What is the critical mathematical operation that occurs repeatedly during the dictionary attack to generate the Pairwise Master Key (PMK) for each guessed passphrase?

    Wireless Network Hacking

    • A. AES Encryption
    • B. PBKDF2 Hashing
    • C. RC4 Key Scheduling
    • D. SHA-256 Hashing
    Show answer

    B. PBKDF2 Hashing

    PBKDF2 (Password-Based Key Derivation Function 2) is used in WPA/WPA2-Personal to derive the Pairwise Master Key (PMK) from the passphrase and the SSID. This computationally intensive hashing function is the core of offline dictionary attacks, as it must be performed for every guessed passphrase.

  21. 21. A cybersecurity team is investigating a reported unauthorized access to their internal wireless network. Logs show a sudden spike in deauthentication frames targeting multiple legitimate client devices, immediately followed by connections to a rogue access point. Which wireless attack technique does this sequence of events strongly suggest?

    Wireless Network Hacking

    • A. Evil Twin Attack
    • B. WPS Pixie Dust Attack
    • C. ChopChop Attack
    • D. Jamming Attack
    Show answer

    A. Evil Twin Attack

    The sequence of deauthentication frames followed by client connections to a rogue AP is a classic indicator of an Evil Twin attack. Deauthentication is often used to force clients off the legitimate AP so they will automatically connect to the attacker's rogue AP.

  22. 22. A penetration tester is performing a wireless assessment on a corporate network. They discover an access point that is broadcasting a hidden SSID and is configured with WPA2-Personal. The tester attempts to capture a 4-way handshake, but no active clients are connected. To force a handshake capture, the tester uses a tool to send a deauthentication packet to a client that is associated with the target AP from a distance. Which specific 802.11 frame type is the tester leveraging for this action?

    Wireless Network Hacking

    • A. Beacon frame
    • B. Deauthentication frame
    • C. Probe request frame
    • D. Association request frame
    Show answer

    B. Deauthentication frame

    A deauthentication frame is an 802.11 management frame used to disconnect a client from an access point. Attackers can spoof these frames to force clients to reauthenticate, thereby generating a 4-way handshake that can be captured for cracking WPA/WPA2-Personal keys.

  23. 23. A network administrator is designing a secure wireless network for a new office. The requirements include strong encryption, mutual authentication using certificates, and protection against common wireless vulnerabilities like key reinstallation attacks. Which combination of security protocols and authentication methods would best meet these criteria?

    Wireless Network Hacking

    • A. WPA2-Enterprise with PEAP
    • B. WPA3-Personal with SAE
    • C. WPA3-Enterprise with EAP-TLS
    • D. WPA2-PSK with AES
    Show answer

    C. WPA3-Enterprise with EAP-TLS

    WPA3-Enterprise offers the highest level of security, including protection against KRACK-like attacks through improved key management. EAP-TLS provides strong mutual authentication using digital certificates, which is more robust than password-based methods like PEAP or PSK.

  24. 24. A penetration tester is evaluating the security of an industrial control system (ICS) wireless network that utilizes legacy 802.11b devices. The network is configured with WEP encryption. Which tool is specifically designed to exploit WEP's vulnerabilities by injecting packets and later cracking the key using statistical analysis of IVs?

    Wireless Network Hacking

    • A. Metasploit
    • B. Kismet
    • C. Aircrack-ng
    • D. Wireshark
    Show answer

    C. Aircrack-ng

    Aircrack-ng is a suite of tools specifically designed for cracking WEP and WPA/WPA2 keys. Its 'aircrack-ng' component uses various statistical attacks, including those based on IV analysis, to recover WEP keys by collecting sufficient data.

  25. 25. A penetration tester is analyzing a web application that stores user session IDs in cookies. The tester notices that the session ID remains constant even after a user logs out and then logs back in. This behavior could indicate a vulnerability related to session management. Which specific attack could exploit this flaw?

    Web Application Hacking

    • A. Insecure Direct Object Reference (IDOR)
    • B. Cross-Site Scripting (XSS)
    • C. Session Hijacking
    • D. Session Fixation
    Show answer

    D. Session Fixation

    If a session ID remains constant after logout and re-login, it indicates that the server is not invalidating and regenerating session IDs properly. This specific flaw is a classic condition for a Session Fixation attack, where an attacker can provide a victim with a pre-determined session ID, and if the victim logs in with it, the attacker can then use that same ID to impersonate the victim.

EC-Council Certified Ethical Hacker (CEH) v12 flashcards

Tap a card to flip it. 189 flashcards in the full deck.

  • WPA2-Personal PSK Cracking

    Flip card

    Recovering the Pre-Shared Key (PSK) for a WPA2-Personal network, typically after capturing a 4-way handshake, often involves offline dictionary or brute-force attacks.

    • Requires capturing the 4-way handshake between a client and AP.
    • Attacks are performed offline against the captured handshake.
    • PSK strength directly impacts the feasibility of cracking.
    Study this card →
  • Kismet Wireless Sniffer

    Flip card

    Kismet is a powerful open-source wireless network detector, sniffer, and intrusion detection system. It passively collects 802.11 frames to discover wireless networks (APs and clients), SSIDs, detect hidden networks, and identify rogue access points or other wireless anomalies.

    • Operates in passive mode, avoiding active probing.
    • Analyzes raw 802.11 frames (beacon, probe, data).
    • Used for network discovery, mapping, and intrusion detection.
    Study this card →
  • WPA3-Personal SAE

    Flip card

    Simultaneous Authentication of Equals (SAE) is the key exchange protocol used in WPA3-Personal, replacing the WPA2 4-way handshake, to provide stronger security against offline dictionary attacks.

    • Mandatory for WPA3-Personal networks.
    • Provides forward secrecy and resistance to side-channel attacks.
    • Makes passive offline dictionary attacks significantly harder or impossible.
    Study this card →
  • 2.4 GHz Interference Sources

    Flip card

    The 2.4 GHz Wi-Fi frequency band is prone to interference from a multitude of non-Wi-Fi devices, including microwave ovens, cordless phones, Bluetooth devices, and baby monitors, due to their shared use of this unlicensed spectrum.

    • Shared with many common household and industrial devices.
    • Fewer non-overlapping channels (3 in most regions).
    • Leads to slower speeds and unreliable connections if not properly managed.
    Study this card →
  • Aireplay-ng Deauthentication

    Flip card

    Aireplay-ng is a tool within the Aircrack-ng suite used to inject frames into a wireless network, most notably for deauthentication attacks to capture WPA/WPA2 handshakes.

    • Part of the Aircrack-ng suite.
    • Used to send deauthentication frames to clients.
    • Forces clients to reconnect, allowing handshake capture for cracking.
    Study this card →
  • Evil Twin Attack

    Flip card

    A type of attack where a rogue wireless access point (AP) mimics a legitimate one, often using the same SSID, to trick unsuspecting users into connecting to it. Once connected, the attacker can intercept, monitor, or manipulate their network traffic.

    • Uses a rogue AP with a spoofed SSID.
    • Often targets open or easily guessable networks.
    • Facilitates man-in-the-middle attacks.
    Study this card →
  • Kismet Wireless Reconnaissance

    Flip card

    Kismet is a passive wireless network detector, sniffer, and intrusion detection system that identifies wireless networks, clients, and their relationships without actively transmitting.

    • Operates in passive mode, minimizing detection.
    • Identifies APs, clients, SSIDs (including hidden ones).
    • Can visualize network topology and client-AP associations.
    Study this card →
  • PEAP (MSCHAPv2) Offline Cracking

    Flip card

    PEAP (Protected Extensible Authentication Protocol) using MSCHAPv2 as its inner authentication method can be vulnerable to offline dictionary attacks if the MSCHAPv2 hashes are captured within EAPOL frames.

    • PEAP creates an encrypted tunnel for inner EAP methods.
    • MSCHAPv2 is a common inner method, but its hashes can be cracked offline.
    • Tools like EAPHammer or Responder can be used to capture and crack these hashes.
    Study this card →
  • 802.11w (Management Frame Protection)

    Flip card

    An IEEE standard that enhances wireless network security by providing integrity protection and confidentiality for management frames (such as deauthentication, disassociation, and beacon frames). This prevents attackers from forging these frames to disrupt network operations or perform denial-of-service attacks.

    • Protects management frames from spoofing and tampering.
    • Uses Message Integrity Check (MIC) for integrity.
    • Crucial for mitigating deauthentication and disassociation DoS attacks.
    Study this card →
  • WPA/WPA2 4-Way Handshake MIC

    Flip card

    The Message Integrity Code (MIC) is a cryptographic checksum included in the WPA/WPA2 4-way handshake messages. It ensures the integrity of the handshake messages and is critical for offline passphrase cracking, as a correct passphrase will yield a matching MIC.

    • Verifies integrity of handshake messages.
    • Calculated using the Pairwise Transient Key (PTK).
    • Used to confirm a guessed passphrase in offline cracking.
    Study this card →
  • WPS Reaver Attack

    Flip card

    The Reaver attack is an online brute-force attack against Wi-Fi Protected Setup (WPS) PINs. It exploits a design flaw in WPS where the Access Point (AP) confirms the correctness of the first four digits of the PIN and the last three digits (plus checksum) separately, effectively dividing an 8-digit PIN into two smaller, easier-to-brute-force sections.

    • Exploits WPS PIN validation in two halves.
    • Significantly reduces brute-force attempts.
    • Typically an online attack, can be slow but effective.
    Study this card →
  • MAC Address Filtering Bypass

    Flip card

    MAC address filtering, a basic wireless security measure, can be easily bypassed by an attacker who spoofs the MAC address of an authorized device.

    • Relies on the uniqueness of MAC addresses for access control.
    • MAC addresses are easily discoverable for active clients.
    • Spoofing allows an attacker to impersonate an authorized device.
    Study this card →
  • 802.11w (PMF)

    Flip card

    IEEE 802.11w, or Protected Management Frames (PMF), is a standard that enhances wireless network security by protecting management frames from tampering and spoofing.

    • Protects deauthentication, disassociation, and other management frames.
    • Mitigates denial-of-service attacks against wireless networks.
    • Mandatory in WPA3 for enhanced security.
    Study this card →
  • Wireless Denial-of-Service

    Flip card

    Wireless Denial-of-Service (DoS) attacks aim to prevent legitimate users from accessing a wireless network or its services, often by overwhelming the access point or exploiting vulnerabilities.

    • Can involve deauthentication floods, jamming, or exploiting AP vulnerabilities.
    • Impacts availability of the wireless network.
    • Targeted attacks against AP firmware are a specific form of DoS.
    Study this card →
  • 5 GHz Interference Sources

    Flip card

    Various devices can cause interference in the 5 GHz wireless band, impacting Wi-Fi network performance and reliability.

    • 5 GHz Wi-Fi offers higher bandwidth and less congestion than 2.4 GHz.
    • Sources of interference include radar, satellite communication, and certain cordless phones.
    • Dynamic Frequency Selection (DFS) is used by Wi-Fi to avoid radar interference.
    Study this card →
  • Rainbow Table Limitations in WPA2-Personal

    Flip card

    Rainbow tables are generally inefficient for cracking WPA2-Personal due to the use of the SSID as a salt in the PBKDF2 key derivation function. This requires a unique rainbow table to be precomputed for each potential SSID, rendering the approach impractical for universal attacks.

    • SSID acts as a salt during PMK generation.
    • Different SSIDs produce different PMKs for the same passphrase.
    • Requires a separate rainbow table for each SSID, making it unscalable.
    Study this card →
  • Enhanced Open (OWE)

    Flip card

    Enhanced Open (Opportunistic Wireless Encryption) is a Wi-Fi standard (integrated into WPA3) that provides individualized data encryption for open, public Wi-Fi networks. It secures communication between the client and the access point without requiring any pre-shared key or user authentication credentials.

    • Provides opportunistic encryption for open Wi-Fi.
    • Based on Diffie-Hellman key exchange for per-client session keys.
    • Protects against passive eavesdropping on open networks.
    Study this card →
  • PEAP (Protected Extensible Authentication Protocol)

    Flip card

    A protocol that encapsulates EAP (Extensible Authentication Protocol) methods within a TLS (Transport Layer Security) tunnel, providing secure authentication, especially for username/password-based systems over 802.1X networks.

    • Commonly used with WPA2-Enterprise and 802.1X.
    • Establishes a secure TLS tunnel before client authentication.
    • Protects EAP methods like MSCHAPv2 from eavesdropping.
    Study this card →
  • EAP-TLS Mutual Authentication

    Flip card

    EAP-TLS (Extensible Authentication Protocol-Transport Layer Security) uses digital certificates for mutual authentication, where both the client and the authentication server verify each other's identity.

    • Requires a Public Key Infrastructure (PKI).
    • Provides strong protection against Man-in-the-Middle attacks.
    • Client trusts the server's certificate, and the server trusts the client's certificate.
    Study this card →
  • PBKDF2 in WPA/WPA2

    Flip card

    PBKDF2 (Password-Based Key Derivation Function 2) is a key stretching algorithm used in WPA/WPA2-Personal to derive the Pairwise Master Key (PMK) from the human-readable passphrase (PSK) and the SSID. Its iterative nature makes offline brute-force attacks computationally expensive.

    • Takes passphrase, salt (SSID), iteration count, and key length as input.
    • Generates the 256-bit PMK.
    • Core component of WPA/WPA2-Personal security, and its weakness to dictionary attacks.
    Study this card →
  • Evil Twin Attack Facilitation

    Flip card

    An Evil Twin attack often uses deauthentication frames to disconnect legitimate clients from their access points, compelling them to search for and connect to the attacker's rogue access point, which mimics the legitimate network's SSID.

    • Deauthentication forces clients off network.
    • Clients automatically search for known SSIDs.
    • Rogue AP receives connections, enabling traffic interception.
    Study this card →
  • 802.11 Deauthentication Frame

    Flip card

    An 802.11 deauthentication frame is a management frame used to terminate an existing connection between a wireless client and an access point.

    • It is an unauthenticated frame, making it vulnerable to spoofing.
    • Attackers use it to force clients to disconnect and reauthenticate.
    • This action generates a 4-way handshake, which can be captured for cracking.
    Study this card →
  • WPA3-Enterprise with EAP-TLS

    Flip card

    The most secure current wireless standard combining WPA3's enhanced cryptographic protections and key management with EAP-TLS for robust mutual authentication using digital certificates, offering superior defense against various wireless attacks.

    • WPA3 provides Forward Secrecy and improved key management.
    • EAP-TLS uses client and server certificates for mutual authentication.
    • Offers the strongest protection against passive eavesdropping and impersonation.
    Study this card →
  • Aircrack-ng for WEP Cracking

    Flip card

    Aircrack-ng is a powerful suite of tools used for auditing and cracking WEP and WPA/WPA2 wireless networks. For WEP, it leverages vulnerabilities like weak Initialization Vectors (IVs) and packet injection to gather enough data to statistically derive the WEP key.

    • Uses statistical attacks (e.g., FMS attack).
    • Requires collecting a large number of IVs.
    • Can perform packet injection to accelerate IV collection.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.