CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium

A client has requested a wireless security assessment to detect unauthorized access points near their headquarters. Which tool is BEST suited for passively capturing SSIDs, BSSIDs, channels, and encryption types from nearby wireless networks?

  1. ANikto
  2. BKismet
  3. CResponder
  4. DNessus
Show answer & explanation

Correct answer: B. Kismet

Kismet is a wireless network detector and sniffer that passively captures 802.11 frames to identify SSIDs, BSSIDs, channels, and encryption schemes, making it ideal for rogue AP discovery. Nikto and Nessus are vulnerability scanners for web apps/hosts, and Responder is used for LLMNR/NBT-NS poisoning on wired/wireless LANs, not passive wireless discovery.

Why the other options are wrong

  • A. Nikto scans web servers for vulnerabilities, unrelated to wireless discovery.
  • C. Responder poisons name resolution requests, it does not passively enumerate wireless networks.
  • D. Nessus is a general vulnerability scanner, not a wireless discovery tool.

Wireless Discovery with Kismet

Kismet is a passive 802.11 wireless network detector, sniffer, and intrusion detection tool used to enumerate nearby wireless access points and clients.

  • Passively captures beacon and probe frames
  • Identifies SSID, BSSID, channel, and encryption type
  • Useful for detecting rogue or unauthorized access points

Memory trick: Passive Scan, Channel Hop, Capture Beacons, Spot Rogues, Map Signal

More Vulnerability Discovery and Analysis questions