EC-Council Certified Ethical Hacker (CEH) v12Wireless Network HackingMedium

A penetration tester is analyzing a wireless network that uses WPA2-Enterprise with 802.1X authentication. During the reconnaissance phase, they observe that the network requires users to input their domain credentials. Which authentication protocol is most likely being used in conjunction with 802.1X for this scenario?

  1. ALEAP
  2. BWEP
  3. CPEAP
  4. DTKIP
Show answer & explanation

Correct answer: C. PEAP

PEAP (Protected Extensible Authentication Protocol) is commonly used with WPA2-Enterprise and 802.1X to encapsulate EAP methods like MSCHAPv2 within a TLS tunnel, allowing secure transmission of credentials like usernames and passwords.

Why the other options are wrong

  • A. LEAP is an older, proprietary Cisco protocol known for vulnerabilities and is less common in modern WPA2-Enterprise deployments.
  • B. WEP is a deprecated encryption protocol, not an authentication protocol, and is highly insecure.
  • D. TKIP is an encryption protocol used with WPA, not an authentication protocol, and is not used with WPA2-Enterprise for credential handling.

PEAP (Protected Extensible Authentication Protocol)

A protocol that encapsulates EAP (Extensible Authentication Protocol) methods within a TLS (Transport Layer Security) tunnel, providing secure authentication, especially for username/password-based systems over 802.1X networks.

  • Commonly used with WPA2-Enterprise and 802.1X.
  • Establishes a secure TLS tunnel before client authentication.
  • Protects EAP methods like MSCHAPv2 from eavesdropping.

Memory trick: Enterprise networks Protect Credentials with Strong Tunnels.

More Wireless Network Hacking questions