CompTIA A+ Core 1 (220-1201)NetworkingHard
A security auditor discovers that a SOHO router has a feature enabled that allows new wireless devices to join the network by pressing a physical button instead of entering the WPA2 passphrase. The auditor recommends disabling this feature because it is vulnerable to a PIN brute-force attack. Which feature should be disabled?
- AWPS
- BQoS
- CUPnP
- DMU-MIMO
Show answer & explanationAnswer & explanation
Correct answer: A. WPS
Wi-Fi Protected Setup (WPS) allows devices to join a network via a push button or PIN, but its 8-digit PIN implementation is vulnerable to brute-force attacks that can expose the WPA2 passphrase, so security best practice is to disable it.
Why the other options are wrong
- B. QoS prioritizes network traffic types and is unrelated to authentication vulnerabilities.
- C. UPnP automatically opens ports for applications and is a different security risk unrelated to PIN attacks.
- D. MU-MIMO improves simultaneous data throughput to multiple devices and has no PIN vulnerability.
WPS (Wi-Fi Protected Setup)
WPS is a feature allowing easy wireless network joining via a push button or PIN, but its PIN method is vulnerable to brute-force attacks and should be disabled for security.
- Push-button or 8-digit PIN method for joining Wi-Fi
- PIN method vulnerable to brute-force attacks
- Best practice is to disable WPS on SOHO routers
Memory trick: 'WPS' = 'Weak PIN Security' — easy button, easy breach.