CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A tester is attempting to capture a WPA2 four-way handshake, but the target client has been idle for over an hour with no new authentication traffic. Which technique should the tester use to force a new handshake capture?

  1. AKarma attack
  2. BARP spoofing
  3. CWPS PIN brute force
  4. DDeauthentication attack
Show answer & explanation

Correct answer: D. Deauthentication attack

A deauthentication attack sends spoofed deauth frames to force the client to disconnect and reauthenticate, generating a new four-way handshake that can be captured with tools like airodump-ng. ARP spoofing manipulates local network traffic, a Karma attack lures clients to a rogue AP by responding to probe requests, and WPS brute force targets the WPS PIN, not the handshake.

Why the other options are wrong

  • A. Karma attacks impersonate networks to attract clients, not force reconnection to the current AP.
  • B. ARP spoofing manipulates traffic routing, it does not force reauthentication.
  • C. WPS brute force attacks the WPS PIN mechanism, unrelated to handshake capture.

WPA2 Handshake Capture

An attacker captures the WPA2 four-way handshake between client and AP, often forcing reauthentication via a deauthentication attack to speed up capture.

  • Deauth frames force client disconnect/reconnect
  • Handshake captured with airodump-ng
  • Cracked offline with hashcat mode 22000 or aircrack-ng

Memory trick: 'Deauth to force the handshake to happen again'

More Attacks and Exploits questions