CWSP practice questions
CWNP · CWSP-208 · 300 questions
Original practice questions for the CWNP Certified Wireless Security Professional (CWSP-208) exam, covering wireless security policy, vulnerabilities and attacks, WLAN security design and architecture, and security lifecycle management.
This course contains the use of artificial intelligence.
About the CWSP-208 exam
- Exam fee
- $349.99 USD
- Time allowed
- 1 hour 30 minutes
- Questions
- 60 multiple choice
- Passing score
- 70% (80% for instructors)
- Format
- CWNP remote proctored exam
Exam details published by the vendor, checked 25 August 2026. Vendors change fees and formats without notice — confirm on the vendor's own page before you book.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
Security Policy · 30 questions
- A city retail concession on the waterfront must process card payments over Wi-Fi for POS tablets. Which WLAN security requirement best reflects PCI-DSS expectations for that wireless path?
- A county clinic is rolling out clinic-wide Wi-Fi for clinician tablets that may display ePHI. What should the WLAN security requirements gathering emphasize under HIPAA-oriented expectations?
- A European municipal visitor center will collect guest email addresses through the Wi-Fi captive portal for marketing. Which requirement should WLAN security policy work incorporate under GDPR?
- A regional transit agency asks for "strong Wi-Fi security" but has not written business goals for ops tablets versus public rider Wi-Fi. What should the security professional do first when forming WLAN security requirements?
- Municipal IT drafts a citywide wireless security policy without involving legal, compliance, or facilities. Which gap most undermines an enforceable WLAN security policy?
- A county hospital redesigns clinical Wi-Fi but omits clinical engineering and biomedical device owners from requirements workshops. Why is that a stakeholder problem for WLAN security policy?
- A city WLAN security review inventories only access points and ignores controllers, RADIUS, and DHCP. What should the infrastructure review include for security requirements?
- Before writing WLAN policy, a municipal warehouse team inventories only managed laptops and skips BYOD phones and barcode scanners. Which requirements input is missing?
- A city warehouse adds rugged scanners that only support an older TLS stack. How should that client constraint affect WLAN security requirements?
- A state university WLAN review finds consumer mesh extenders bridged onto the campus staff SSID. What should the infrastructure review conclude for policy?
- Technical requirements say "encrypt everything," but the city council needs board-readable WLAN security policy. What should the security professional produce?
- A draft municipal WLAN policy lists a single vendor's product SKUs instead of security outcomes. Which rewrite best follows high-level policy practice?
- City leadership wants WLAN security policy "based on industry standards" without inventing home-grown crypto rules. What advice aligns with CWSP policy practice?
- A small municipal office proposes copying a 2008 WLAN policy template that still allows WEP. What should the advisor recommend?
- A county writes WLAN security policy once, then never revisits it after major controller and WPA3 upgrades. Which lifecycle action is missing?
- After a city adopts WPA3-Enterprise, temporary WPA3 Transition Mode exceptions remain in policy with no end date. What lifecycle practice should be applied?
- Network engineers publish a city WLAN security policy on an internal wiki with no executive sign-off. What is required before the policy can be treated as enforceable?
- A public school district needs enforceable acceptable-use rules for guest Wi-Fi used by visitors and events. Who should approve that guest WLAN policy content?
- Helpdesk staff at a municipal utility still tell employees to share the staff WLAN PSK. Which Domain 1 control most directly addresses this behavior?
- New contractors arrive on a city plant floor with no briefing on how to report suspected rogue APs. What should WLAN security awareness cover for these stakeholders?
- City finance purchases outdoor APs "for cameras" and ships them for install without a security review. What Domain 1 practice was skipped?
- A city museum wants open Wi-Fi for visitors and a separate secured WLAN for exhibit sensors. How should security requirements be derived?
- A municipal WLAN policy lists only the CISO as owner; network operations never receives updates. Which stakeholder gap should be fixed?
- An audit finds city policy mandates certificate-based EAP, but nobody reviewed which line-of-business apps break with mutual TLS client auth. What requirements step was skipped?
- A county WLAN moves to cloud-managed controllers, but security policy still assumes only on-premises admin paths. What should the infrastructure requirements review update?
- A county WLAN draft only says staff shall not do bad things on Wi-Fi and lists no enforceable rules. How should the security lead rewrite it into high-level policy statements?
- Industry hardening guidance for the city's WLAN controllers calls for unique administrator credentials and disabling legacy SNMP. What should the CWSP advise when building WLAN security policy?
- A municipal WLAN security policy was approved last year, but no review calendar exists. What lifecycle step is missing?
- City IT enables aggressive WIPS blocking on the civic-center WLAN without documented approval, and facilities staff complain that legitimate devices are disrupted. What should have happened first?
- The county's quarterly phishing drills only use email lures and never mention fake captive portals or evil-twin Wi-Fi prompts. What awareness gap should the CWSP flag?
Vulnerabilities, Threats, and Attacks · 90 questions
- A new AP firmware advisory appears in a CVE feed for the city's campus WLAN vendor. What is the most appropriate first use of that information source?
- The vendor PSIRT publishes a remote code execution advisory for the municipal WLAN controller, but staff only read informal news blogs. Which guidance is best?
- An IoT badge reader used at county building doors has a published CVE in its Wi-Fi module. How should WLAN vulnerability scope treat that finding?
- After a major WPA2-class vulnerability headline, city security asks whether municipal Wi-Fi is affected. What should the CWSP do next?
- A regional library consortium runs many APs and controllers but has no process to watch CVE or vendor advisories for WLAN gear. What gap should be called out?
- Open-source RADIUS used for 802.1X on the transit-authority WLAN has a published CVE. How should vulnerability tracking treat that system?
- A CVE for a city hall AP requires physical console access to exploit. After recording the CVE, how should impact judgment differ from a remote wireless exploit?
- A critical remote exploit targets internet-exposed cloud WLAN dashboards used by the municipality, while another AP bug is local-only on an isolated management VLAN. How should relative risk be rated?
- A guest SSID isolation failure on city visitor Wi-Fi could expose the payment VLAN used by municipal cashiers. What should dominate the impact assessment?
- A deauthentication flood hits the city's VoWLAN used by public-safety and facilities radios. How should impact primarily be framed?
- An unpatched WEP pop-up kiosk on the county fairgrounds seems low risk until engineers discover it bridges onto the corporate WLAN. What does impact analysis require?
- A controller vulnerability for the municipal WLAN requires valid administrator credentials before it can be exploited. How should that affect remote risk relative to an unauthenticated wireless exploit?
- The same AP CVE appears on a closed city IT lab WLAN and on production stadium Wi-Fi serving tens of thousands of fans. How should risk differ?
- During a city risk meeting, staff treat a high CVSS number as the complete WLAN risk rating and ignore likelihood and local business impact. What correction is needed?
- Municipal policy requires WPA3, but an SSID still allows TKIP. What mitigation best addresses that finding?
- A vendor releases a patch for a critical CVE on the city's WLAN controllers. What is the appropriate mitigation when a fix exists?
- A compromised municipal AP cannot be patched yet. What mitigation should the CWSP select in the meantime?
- After suspicious 802.1X authentication failures on the courthouse WLAN, engineers skip logs and packet review. What mitigation and verification step is missing?
- Auditors find an open management SSID on the city's WLAN that violates written security policy. What is the primary mitigation?
- A zero-day affects AP OS images on the municipal mesh with no vendor patch yet, but compensating WIPS signatures are available. What mitigation approach fits best?
- A county facilities closet reveals a compromised rogue access point plugged into a live switch port on the municipal staff VLAN. Besides removing the device, which mitigation best contains the wired attachment risk?
- A city WLAN vendor releases a fixed AP code train for a known vulnerability, but the municipal change window is next week. What mitigation approach best fits until the upgrade can run?
- Config audits show drift re-enabled cleartext HTTP administration on several library-branch access points that policy requires to use HTTPS-only management. What remediation best restores policy conformance?
- An attacker outside a municipal community center records unprotected 802.11 frames on the city’s open public cafe-style SSID. Which threat does this scenario primarily illustrate?
- Workers near city hall associate to a fake access point that advertises the corporate municipal SSID and presents a look-alike login to harvest credentials. Which attack pattern best describes this?
- A researcher captures a WPA2-Personal 4-way handshake from a parks-department shared staff SSID that uses a short dictionary passphrase, then runs an offline password guess against that handshake. Which WLAN attack does this demonstrate?
- County employees receive SMS messages saying “update your Wi-Fi password” with a link to a fake portal that asks for municipal network credentials. Which attack category best fits?
- During a civic-center incident review, analysts see bursts of deauthentication frames that force laptops to reconnect while a nearby adversary captures handshakes. What is the best characterization of this technique?
- At a downtown transit hub, a malicious responder answers preferred-network probes from city tablets for popular SSIDs the devices remember, luring them to associate. Which attack behavior is this?
- A shared parks-and-recreation staff PSK for a WPA2-Personal SSID appears on a public paste site. Beyond immediate key rotation, which risk statement is most accurate?
- An insider at a municipal court annex runs a soft AP on a laptop that bridges the guest SSID segment onto the staff VLAN. Which attack path does this primarily represent?
- During a city council Wi-Fi outage drill, clients see dozens of rapidly appearing fake SSIDs and struggle to find the legitimate municipal network. Which attack best matches this symptom?
- A field locker-room AP in a city recreation center still has WPS PIN enrollment enabled contrary to hardening standards. Which threat should security staff highlight?
- A spear-phishing campaign against finance staff at city hall installs a malicious wireless profile that prefers an attacker-controlled SSID. How does this social-engineering outcome enable further WLAN compromise?
- Municipal WIPS alerts on an access point advertising the corporate city SSID with an unknown BSSID and fingerprint not in the authorized inventory. What should analysts conclude they have detected?
- Protocol analysis for a transit-yard WLAN shows unusual deauthentication spikes that correlate with sudden client drops. Which detection conclusion is most appropriate?
- The city’s SIEM correlates repeated RADIUS rejects from one wireless MAC with physical door-badge misuse events for the same employee badge ID. What detection capability does this illustrate?
- Library patrons and remote staff report look-alike captive portals when off campus, prompting the security desk to open tickets. How do these reports function in WLAN attack detection?
- Security reviewers note that offline PSK cracking leaves little live RF noise on the city WLAN. Where should detection effort focus for this risk?
- Integrated AP sensors in a municipal conference wing flag an ad-hoc soft AP running on an attendee laptop. What has the WLAN security system most likely detected?
- A protocol analyzer at the utilities operations center shows a supposed enterprise staff SSID offering open authentication instead of 802.1X. What eavesdropping-related condition has been detected?
- An overlay WIPS deployment places a rogue transmitter on the city-hall floor map using RF location. Which detection capability is being demonstrated?
- Traffic analysis on the municipal guest VLAN shows scanning probes toward staff subnets that policy says must remain isolated. What does this monitoring result indicate?
- The wireless security lead for a county clinic WLAN must mitigate eavesdropping against sensitive traffic. Which mitigation best matches CWSP guidance?
- City IT wants to mitigate evil-twin MITM against the staff enterprise SSID used in civic offices. Which combination best aligns with recommended mitigations?
- A county parks department shares one WPA2-Personal passphrase across maintenance tablets. After a staff laptop is stolen with the passphrase saved, offline cracking of captured handshakes becomes a realistic risk. Which mitigation best reduces that cracking exposure going forward?
- City employees keep entering civic credentials into look-alike captive portals while traveling. Which WLAN phishing mitigation best reduces successful credential theft?
- A municipal library’s public SSID experiences repeated client disconnect storms consistent with spoofed deauthentication frames. Which mitigation pair best reduces impact?
- A town hall WLAN still has Wi-Fi Protected Setup enabled on corridor APs used for guest and staff onboarding. Which mitigation best addresses enrollment PIN attacks?
- County free Wi-Fi in the permit office allows guest devices to reach each other on the same SSID. Which mitigation best reduces client-to-client attacks on that guest WLAN?
- After a transit-yard shared PSK appears in a public paste site, which remediation best restores WLAN credential hygiene?
- WIPS locates a rogue AP bridged onto a city-hall switch closet and advertising a look-alike staff SSID. Per policy, which containment approach is most appropriate?
- A warehouse barcode SSID for a municipal supply depot still uses WEP. What should the CWSP conclude about that security solution?
- A city conference-room transition SSID still negotiates TKIP for older laptops. How should the security engineer treat TKIP?
- Marketing Wi-Fi for a civic festival is still labeled only 'WPA' on the controller profile, not WPA2 or WPA3. What is the correct assessment?
- During a county WLAN architecture review, RC4 appears in a cipher-suite discussion for air encryption. How should RC4 be classified for Wi-Fi security?
- Vendor default profiles on city APs include a 'WPA/WPA2 mixed' mode that still enables TKIP for compatibility. How should that default be treated?
- An auditor asks why the city’s staff SSID uses CCMP instead of TKIP. What is the best explanation?
- A museum exhibit controller only supports WEP. A technician suggests hiding the SSID so WEP is 'safe enough.' What is the correct mitigation approach?
- Before a WLAN penetration test of county buildings, what must the team establish first?
- During a civic WLAN security assessment, testers compile SSID inventories, AP locations, and client device types before launching active attack techniques. Which phase does this describe?
- Testers enumerate encryption modes on city SSIDs and probe open management ports on wireless controllers before any exploitation attempts. Which pen-test phase is this?
- During the attack phase of a school-district WLAN test, which practice is correct?
- After WLAN security testing at a county clinic, what documentation practice is required?
- An auditor must inspect EAPOL handshake exchanges on a city staff SSID. Which tool class is the appropriate selection for that task?
- A municipal IT team must verify encryption and authentication modes on every civic SSID before an annual review. Which approach best fits that goal?
- When are Kali Linux wireless toolkits appropriate in a city WLAN security program?
- A county tester needs reliable monitor-mode captures outdoors near a water-treatment plant WLAN. How should hardware be selected?
- Which project-documentation practice best supports a repeatable municipal WLAN security test?
- A helpful intern begins scanning and attempting associations against city SSIDs without written approval, calling the activity a 'security test.' What is the correct CWSP assessment?
- A city WLAN team sees WIPS alerts, RADIUS rejects, and switchport flapping but they live in separate consoles. Which monitoring approach best correlates those events centrally?
- A county wants dedicated RF security coverage that keeps watching even if serving access points are busy or misconfigured. Which WIPS model fits?
- A municipal IT director asks how integrated WIPS differs from overlay for city hall Wi-Fi. What is the accurate tradeoff?
- A city hosts a weekend pop-up civic festival with temporary Wi-Fi and needs short-term RF security watching without permanent sensors. Which approach fits?
- A multi-campus school district must watch WLAN security at every site. Why choose distributed collectors over a single central poller alone?
- During a library WLAN redesign, staff confuse WIDS with WIPS. Which statement correctly separates the roles?
- A mayor asks why the city still funds ongoing WLAN monitoring after writing a strong wireless policy. What is the best justification?
- A transit agency already runs overlay WIPS. How should RF security events become actionable operations tickets with identity and network context?
- Before rating WLAN risks for a civic data center Wi-Fi plant, what asset-management step must come first?
- A hospital WLAN risk review omitted wireless IoT infusion pumps from the asset list. Why does that understate risk?
- A hospital SSID misconfiguration could expose clinical workflows. How should the WLAN risk rating be formed?
- Two WLAN flaws have similar impact: one needs rare physical console access; the other is a common remote wireless exploit. How should ratings differ?
- A cracked guest bridge could expose cardholder data on a city-run retail kiosk WLAN. What should loss expectancy emphasize?
- Stadium Wi-Fi planners compare one sold-out weekend outage to a year of repeated rogue-AP incidents. Which loss-expectancy framing is sound?
- A county WLAN risk plan must sequence remediation. Which priority order best matches critical deprecated crypto and monitoring gaps?
- A legacy barcode-scanner SSID cannot move off weak crypto this quarter. What must the WLAN risk plan document?
- Why should asset classification treat guest APs differently from payment-terminal APs in a civic arena?
- In a city risk workshop, analysts fear false precision from made-up percentages. How should they still produce usable WLAN risk ratings?
- Estimating loss expectancy for a city council Wi-Fi breach should include which loss categories?
- A draft WLAN risk plan proposes to 'accept WEP forever' with no isolation and no executive signature. What should the plan require instead?
WLAN Security Design and Architecture · 150 questions
- A small municipal field office has no RADIUS server but still needs strong personal-mode Wi-Fi authentication. What should the designer select?
- Home-lab training gear at a county academy only supports WPA2-Personal. How should instructors contrast it with WPA3-Personal?
- Corporate laptops and Active Directory identities exist for city staff. Which WLAN authentication design is appropriate?
- A high-security government WLAN policy demands WPA3-Enterprise 192-bit mode. What should the architect select?
- A civic WLAN design requires port-based network access control for Wi-Fi clients. Which framework provides that model?
- A municipal operations center needs every staff AP to check user credentials against a central AAA store before granting WLAN access. Which authentication service belongs in that design?
- County policy requires mutual certificate authentication for staff laptops on the corporate SSID. Which EAP method best meets that requirement?
- A city library has specialty tablets that cannot store client certificates but can send a username and password inside a TLS tunnel to RADIUS. Which EAP method fits that constraint?
- A transit agency’s Windows-heavy fleet will authenticate to staff Wi-Fi with usernames and passwords protected inside a TLS tunnel, typically using MSCHAPv2. Which EAP method is that common pattern?
- Visitors to city hall need Internet-only Wi-Fi and must not use staff directory credentials. What authentication path should the designer choose?
- Policy forbids a single shared passphrase for roughly 500 municipal employees on the primary staff SSID. Which authentication design complies?
- City utilities IoT sensors cannot perform 802.1X, and operations proposed one global PSK on an open SSID. Which authentication approach is most appropriate for those constrained devices?
- During a county WLAN migration, some staff clients only support WPA2-Enterprise while newer laptops support WPA3-Enterprise. How should authentication be selected?
- When the city’s RADIUS servers are unreachable, engineers propose configuring Enterprise SSID APs to fail open and allow all associations. What is the correct security design stance?
- A county facility must choose guest Wi-Fi authentication: sponsor email approval versus open-on-click self-registration. What should drive the selection?
- A PKI-mature campus already issues managed device certificates and wants the strongest common enterprise WLAN EAP choice among TLS, TTLS, and PEAP. Which selection best fits?
- Retail-facing city HQ wants machines to authenticate to Wi-Fi before user logon and users to authenticate afterward for staff access. Which design direction is appropriate?
- Public kiosk tablets at the clerk’s office will use a guest-style SSID. Why must that SSID avoid the staff RADIUS realm?
- A parks department small site will use Personal mode. Why is WPA3-Personal with SAE preferred over classic WPA2-Personal PSK authentication?
- Contractor badges at a municipal data center map to Active Directory groups that should control Wi-Fi access. Which authentication approach should be selected?
- Security wants to mandate WPA3-Enterprise 192-bit mode on the courthouse SSID. What must be verified first?
- A small municipal field office SOHO-class AP offers WPA3 Transition for Personal mode versus SAE-only. How should the mode be chosen?
- A university-affiliated city training campus wants eduroam-style federated Wi-Fi for visiting researchers. Which authentication pattern is required?
- Guest Wi-Fi at the civic center uses an email click-through portal, while the staff SSID uses PEAP. What design principle should remain true?
- A weekend farmers-market booth network has no certificates, no directory, and only a passphrase for a temporary AP. Which authentication choice fits?
- Enterprise APs at the water utility authenticate users via RADIUS, but the AP-to-AAA shared secret remains the vendor default. What is wrong with that authentication design?
- Policy requires phishing-resistant WLAN authentication using device certificates for municipal laptops. Which EAP method should be selected?
- Guest access for the public library must not accept staff Active Directory passwords on the captive portal. What should the designer do?
- A facilities manager claims hiding the courthouse SSID provides confidentiality for wireless frames. Which statement corrects that misunderstanding?
- For a standard WPA2 enterprise redesign at city hall, which pairwise cipher should replace deprecated TKIP?
- A city library is designing a WPA3-Enterprise SSID for staff tablets. Beyond CCMP, which modern encryption protocol should the security architect also recognize as a valid Galois/Counter Mode option in current Wi-Fi suites?
- During a county hospital WLAN security design review, an engineer asks what cryptographic algorithm underlies both CCMP and GCMP. Which answer correctly separates the algorithm from the protocol wrapper?
- A municipal utilities yard is moving IoT gateways to WPA3-Personal. A technician claims SAE is “the encryption cipher that scrambles every data frame.” How should the security designer correct that statement?
- City cybersecurity policy for a classified records WLAN requires WPA3-Enterprise 192-bit security. Which encryption/AKM selection best matches that requirement?
- A county transit hub wants a password-free public SSID that still protects riders from casual passive sniffing on the RF. Which encryption approach should the architect select?
- Remote county clinicians work from hotel and coffee-shop Wi-Fi to reach clinic EHR apps. Link crypto on those foreign SSIDs is unknown. What additional control should the WLAN security design require for application traffic?
- A new WPA3 WLAN for city hall staff must choose modern data encryption. How should the designer compare CCMP and GCMP at selection time?
- Campus IT proposes terminating every city employee laptop into a VPN concentrator instead of deploying 802.1X on the corporate SSID. What is the sound security-architecture position?
- A parks department guest SSID uses only a captive portal for Acceptable Use acceptance. Auditors ask how RF frames are encrypted for casual visitors. What should the architect explain?
- A vendor proposes enabling TKIP “for compatibility” on a brand-new municipal public-safety WLAN. Which encryption decision aligns with current security design practice?
- While documenting the city council chamber SSID, the architect must explain encryption key roles at a design level. Which statement is accurate?
- County policy requires AES-CCMP for the assessor’s office WLAN and forbids mixed TKIP/AES profiles. A controller template still offers “TKIP+AES” mixed mode. What should the designer do?
- Outside contractors on the city’s guest SSID must reach a few internal project apps without placing those apps on the open guest VLAN. Which control best fits the encryption/security design?
- A city HR pilot wants WPA3-Enterprise 192-bit mode, but many older staff phones lack that suite. What encryption-selection constraint must the architect respect?
- A municipal visitor WLAN still has legacy open clients that cannot perform OWE. Leadership wants encryption for capable devices without stranding the rest overnight. Which OWE deployment choice fits?
- A security whiteboard at the water treatment plant labels “CCMP/GCMP” as protecting all 802.11 management and data frames equally. What correction belongs in the design notes?
- A city stadium Wi-Fi design needs continuous RF security monitoring with dedicated sensors that are not busy serving fans. Which wireless monitoring approach should the architect select?
- A small-town civic center has budget for security monitoring but not a second sensor grid. Serving APs can share scanning duty. Which WIPS approach fits?
- During a county courthouse WLAN cutover, engineers must validate EAPOL exchanges on the new secure SSID. Which on-site monitoring tool best fits that packet-level check?
- After jamming-like symptoms hit the municipal warehouse WLAN, responders need to hunt non-Wi-Fi interference and energy patterns. Which laptop-kit tool should lead that RF investigation?
- Serving APs at a busy city convention center cannot spend enough time off-channel without hurting client performance. Security still needs continuous multi-channel visibility. Which WIPS selection follows?
- City SOC requirements say the WLAN monitoring system must alert when a rogue AP advertises the same corporate SSID. Leadership offers only switch SNMP uptime polls. What capability gap must be closed?
- Before city-wide rollout, a pilot must prove OWE and SAE handshakes complete as designed on sample APs. Which monitoring activity validates that security design?
- A week-long outdoor civic festival needs short-term WLAN security oversight without a permanent sensor build-out. Which monitoring approach is most appropriate?
- In the city’s RSN design guide, what does Authentication and Key Management (AKM) define for an 802.11 Robust Security Network?
- A county facilities WLAN finishes either PSK or 802.1X authentication for building-inspector tablets. What is the primary purpose of the 4-way handshake that follows?
- City IT is retiring WPA2-Personal on the parks-crew SSID because offline dictionary attacks against a shared passphrase keep succeeding in audits. Which WPA3-Personal AKM mechanism should replace that password-based design?
- A municipal library wants an open guest SSID that still encrypts each patron’s unicast traffic without distributing a passphrase. Which exchange enables that opportunistic encryption?
- Transit-authority officers roam between platform APs while staying on a secure enterprise SSID. Which AKM-related construct specifically supports fast secure handoffs under 802.11r?
- A town clerk’s office uses one Wi-Fi passphrase for every inspector laptop under WPA2/WPA3-Personal. Where does that design place the pre-shared key in AKM terms, and what operational risk follows at municipal scale?
- County public-health clinicians authenticate to the clinic WLAN with usernames and certificates through a RADIUS server. In what order does Enterprise AKM establish security for their sessions?
- During a city WLAN design review, the security architect asks how clients learn which AKM suites and pairwise ciphers an AP supports before associating. Which element advertises those RSN capabilities?
- A municipal CIO asks which Wi-Fi Alliance security generation should be treated as deprecated when selecting AKM for new city-hall SSIDs, relative to WPA2 and WPA3.
- Public-works still has a few WPA2-only rugged tablets while newer crew phones support WPA3. Leadership enables WPA3 Transition Mode on the field SSID. What security tradeoff should the CWSP candidate emphasize versus SAE-only?
- Campus Wi-Fi engineers debate two different knobs while migrating city buildings to stronger AKM: WPA3 Transition Mode versus RSN Override. How should a CWSP candidate distinguish them at a conceptual level?
- In a court-house WLAN design workshop, staff confuse PMK, PTK, and GTK roles. Which statement correctly maps the key hierarchy concepts?
- Fire-station tablets use 802.11r while paramedics move through the apparatus bay. At a conceptual AKM/roaming level, how do FT over-the-air and FT over-the-DS differ?
- A parks department insists CCMP is enabled on their Personal SSID, yet auditors still crack the network after capturing a handshake because the passphrase is “Parks2024!”. What AKM lesson should the security lead draw?
- Compared with a single shared PSK on the utilities field SSID, what security property does Enterprise AKM add when linemen authenticate with unique credentials?
- A scan of city-hall beacons during WPA3 migration shows both WPA2 and WPA3 AKM suites advertised on the same SSID. How should the candidate interpret that mixed advertisement?
- The city wants downtown kiosk Wi-Fi to remain passphrase-free for tourists yet still encrypt each device’s unicast frames. Which AKM should the design select for that open SSID goal?
- Clinic tablets receive Access-Accept from RADIUS, yet the 4-way handshake fails and no user-plane traffic flows. Conceptually, what should the municipal WLAN team investigate first among AKM issues?
- After several inspectors leave the permit-counter BSS, the WLAN still needs to refresh keys used for broadcast/multicast frames to remaining stations. Which handshake concept addresses that group-key renewal?
- In a mixed client environment at city libraries, engineers want capable devices to prefer stronger RSN suites rather than settling for weaker transition options. What is the conceptual purpose of RSN Override in that design?
- Policy for new community-center SSIDs requires a WPA3 security baseline. Which deprecated options must the design reject as AKM/cipher choices under that baseline?
- Before approving the next municipal WLAN architecture review, security leadership wants a written allowlist of AKM suites (for example SAE and 802.1X-SHA256) that APs may advertise. Why does that policy artifact matter?
- An auditor notes that unused Ethernet wall jacks in a civic center could let someone plug in a rogue AP. Which wired support control best addresses that physical attachment risk at the switch edge?
- Wiring-closet reviews for county buildings show many switchports enabled with no connected device. What physical/port-security practice should WLAN-supporting network teams apply?
- A city WLAN carries employee laptops, guest tablets, and building IoT sensors on the same SSID and VLAN today. Which segmentation approach best aligns with layered WLAN-supporting security?
- A municipal security architect describes defense-in-depth for WLAN user traffic as it leaves the air and enters the wired campus. Which stacked control set best matches that layered approach?
- A city library WLAN must keep user VLANs centralized on the wireless controller rather than switching locally at each AP. Which architecture pattern best meets that design goal?
- County IT wants guest Wi-Fi traffic kept out of the campus core and terminated in a DMZ. Which approach best supports that isolation goal?
- A municipal guest VLAN must reach the Internet but must not talk to staff servers. Where should ACLs primarily enforce that Internet-only restriction?
- A public health clinic’s IoT WLAN segment must not reach electronic health record (EHR) servers. Which control best limits that lateral movement?
- City hall separates a guest WLAN VLAN from corporate services. Which device role should sit between those segments to inspect and filter that traffic?
- Remote city workers often join from untrusted café Wi-Fi, then VPN into municipal systems. What firewall posture best fits that path?
- Campus switches terminate city APs. Which port-hardening pair best protects those AP attachment points?
- A county WLAN design discussion focuses on microsegmentation after 802.1X. How should WLAN roles typically map for segmentation?
- Remote inspectors use external WLANs and VPN back to county systems. Leadership asks about split-tunnel versus full-tunnel. What is the key security-architecture distinction?
- Guest-to-staff deny ACLs protect a civic WLAN. How should those ACLs also support operations beyond silent blocking?
- A compromised Wi-Fi laptop on the city network begins unusual lateral protocols toward internal hosts. Which control is best positioned to identify that behavior in transit?
- Policy requires least privilege on AP switch drops across city buildings. Which VLAN-trunk practice best matches that hygiene?
- A remote branch must connect its AP/controller WLAN path across the public Internet back to headquarters. Which protection best fits that untrusted WAN transit?
- Designers want an AP switchport to shut if someone swaps the AP for a soft-AP phone bridge. What design intent does a port-security violation shutdown express?
- After login on a hospital-affiliated city clinic WLAN, clinicians and guests must receive different network privileges. Which model best describes that outcome?
- A transit agency wants one enterprise SSID but different network rights per job function. Which RBAC pattern best achieves that?
- The city plans WPA-Enterprise with EAP-TLS for staff laptops. What foundational service must exist for client and server certificates?
- Staff laptops use 802.1X against city RADIUS. Which PKI-dependent client behavior best helps stop an evil-twin AP impersonating the enterprise SSID?
- Architects describe why enterprise WLAN should use AAA rather than only local AP user databases. What purpose do AAA servers primarily serve?
- City WLAN must stay available if one RADIUS server fails, but must not admit users without authentication. Which AAA design best fits?
- Before staff devices first associate to the secure city SSID, credentials or profiles must be installed safely. What does that client-onboarding goal emphasize?
- A university-affiliated municipal campus offers a self-service portal that issues unique WLAN credentials. What design caution still applies?
- County policy requires wireless staff devices to show healthy antivirus posture before receiving the full staff VLAN. Which control implements that gate?
- Some wireless clients fail NAC posture on the city WLAN. Which network response best supports remediation without full staff access?
- Employees bring personally owned phones onto the enterprise city SSID. Which control family best addresses corporate data on those BYOD devices?
- A city IT team manages tablets used by building inspectors on the staff WLAN. How should MDM best reduce evil-twin risk for EAP?
- Contractors authenticate successfully to the municipal Wi-Fi, but policy must still keep them off finance SSID resources. Which control enforces that after authentication?
- Field tablets for public-works crews sometimes lack Internet paths when validating certificates during EAP. What PKI concern should the WLAN security design address?
- After suspicious Wi-Fi logins at city hall, investigators need evidence of who authenticated, when, and from which session. Which AAA function best supplies that telemetry?
- Facilities wants a permanent open SSID named Enroll-City so any device can grab certificates. What onboarding design principle should security enforce instead?
- The county health campus wants posture checks before full staff VLAN access on Wi-Fi. Where does NAC belong in that architecture?
- A council member’s unmanaged personal phone requests the high-trust finance SSID. Policy requires MDM for that SSID. What should the design do?
- WLAN engineers must choose trust anchors for RADIUS server certificates used by city EAP clients. Which design choice is most accurate?
- The city plans to back Wi-Fi identity with a cloud IdP through an AAA proxy. Which architecture statement remains true?
- Headless IoT meters in city facilities cannot run 802.1X clients. What onboarding approach best improves accountability versus one shared PSK?
- Managed phones for code-enforcement staff must be MDM-compliant before gaining staff WLAN rights. How should the controls work together?
- Dispatch voice handsets roam across city-yard APs and drop syllables during full 802.1X each hop. Which secure roaming feature should the design select first?
- A candidate claims Fast BSS Transition simply turns off encryption during roam. What is the correct CWSP-level understanding?
- A mixed-vendor municipal campus needs faster secure reassociation without depending solely on 802.11r client support. Which technique fits that conceptual need?
- For a city voice SSID, engineers must choose between 802.11r FT and OKC. What selection guidance is most appropriate?
- Facilities proposes one shared PSK for all yard tablets because roaming is simple. What security tradeoff must leadership accept?
- Library kiosks and volunteer tablets need Personal-mode Wi-Fi without one citywide passphrase. Which approach improves accountability?
- Some city scanners misbehave with FT enabled, so ops plans to disable it on that SSID. What operational tradeoff should they expect?
- During a design review, staff ask how OKC speeds secure reassociation across city APs. What is the core idea?
- A vendor claims per-user PSK gives the city the same security properties as WPA3-Enterprise 802.1X. What is the accurate distinction?
- Secure transitioning for ambulance tablets across hospital-campus APs must satisfy which rule?
- In a controller-based city WLAN using 802.11r, what conceptual roles do FT key holders play?
- Warehouse barcode scanners fail when 802.11r is enabled on the logistics SSID. What is a reasonable secure-roaming response?
- City visitor Wi-Fi must not reach staff file shares or internal VLANs. Which guest-access design best meets that goal?
- On the public library guest SSID, attackers could pivot laptop-to-laptop if clients talk freely. What control best stops that lateral path?
- A city visitor-center WLAN must show guests an acceptable-use policy and record acceptance before Internet access begins. Which design best meets that goal?
- A municipal tourism board wants visitors’ phones to join partner hotspots automatically with stronger onboarding than a shared PSK poster. Which approach best matches that goal?
- A library board wants a password-free ‘open’ municipal SSID that still encrypts airtime against casual sniffing. Which control should the WLAN designer select?
- A county parks department is hardening free public Wi-Fi. Which guest design best layers public-access controls?
- A city conference-center SSID will host vendor demos that sometimes need AirDrop-like peer-to-peer transfers. How should the security designer treat peer-to-peer policy?
- A town IT lead notices visitors can be tricked by fake captive-portal pages on cleartext HTTP. What hardening direction should CWSP guidance favor?
- Regional transit riders roam across city hotspots and still receive paper PSK cards. Which Passpoint-oriented change best reduces that manual credential problem?
- A civic plaza SSID must encrypt public airtime and still force guests through an AUP page. Which statement is most accurate?
- A borough proposes a downtown ‘open’ SSID with neither a captive portal nor OWE. From a modern public-access security design view, what is the best assessment?
- A city-owned visitor lodge must choose a guest Wi-Fi credential model. How should the WLAN security designer decide between per-room credentials and open+OWE?
- During a municipal WLAN hardening review, outdoor APs and the controller still use factory administrator passwords. What should be done first?
- A city help desk discovers the staff SSID accidentally maps guests to the same open VLAN as employees. What preventative focus best addresses this class of failure?
- County WLAN APs have known CVEs fixed only in newer firmware. Which preventative measure aligns with CWSP infrastructure hardening?
- A municipal WLAN controller still allows cleartext HTTP for the admin GUI. What should the hardening plan require?
- Field techs still use Telnet to the city’s outdoor AP CLI. What preventative change should security mandate?
- A library WLAN still runs SNMPv2c with the community string ‘public’ on APs. What should the designer do?
- A new outdoor AP for a transit shelter still accepts ‘admin/admin’. How should a hardening assessment treat that finding?
- After a template push, several city APs re-enable HTTP admin that security had disabled. What preventative discipline best stops this regression?
- Vendor support ends for AP code that still has unpatched remote flaws on a municipal campus. What preventative path remains when patches will never ship?
- A city WLAN team wants one management-plane hardening baseline for controllers and APs. Which combination best matches preventative practice?
Security Lifecycle Management · 30 questions
- Public works proposes new IoT employee badges that will join the city WLAN. What is the first lifecycle step before enabling them?
- A municipal RF team receives a Wi-Fi 7 AP feature pack. Before flipping features on, what should security lifecycle practice emphasize?
- A county campus wants a new BLE/Wi-Fi location-services overlay. What should happen before enablement?
- A guest-analytics vendor asks a city museum to collect probe requests from visitor devices. What lifecycle action is most appropriate first?
- New warehouse barcode scanners will join a municipal logistics WLAN. After identification and requirements assessment, what should the team do next?
- A county IT office just enabled WPA3 on the municipal staff SSID and wants proof the cutover is secure and usable. What validation step best confirms the protective change worked?
- A city utilities team deployed a new IoT SSID for smart meters and sensors. In the monitor phase of the security lifecycle, what approach best watches the new technology for anomalies?
- A parks department opened a new recreation wing and wants an on-site RF security check before public programs start. Which monitoring method fits a portable audit of the wing’s WLAN security posture?
- A municipal WLAN team needs nightly proof that controller security settings have not drifted from the approved baseline. Which audit approach best matches infrastructure-based configuration auditing?
- After a county adds a new outdoor mesh for trailhead Wi-Fi, which continuous monitoring control best covers the air-side security lifecycle monitor phase?
- A city WLAN lead plans to cut over encryption settings on the employee SSID during a weekend window. Before changing production, what change-management actions are required?
- A town’s SOC pushes an emergency WIPS signature update to stop an active outdoor attack. What change-management expectation still applies after the urgent fix?
- A municipal guest portal needs scheduled downtime for a security fix that will interrupt visitor Wi-Fi at city hall. Which change-management practice is most important for that downtime?
- A county library WLAN shows rising client counts. Leadership wants capacity forecasts, but policy requires client isolation on the public SSID. How should monitoring data be used?
- A county clinic WLAN team sees steady growth in wireless medical devices. What forecasting action best keeps security services ready?
- A city WIPS deployment is expanding sensors into new community centers. What license-management action prevents security coverage gaps?
- A municipal wireless controller needs a security-related code upgrade. What practice best reflects controlled software upgrade management?
- A town WLAN operations team wants secure AP profiles to stay consistent across sites. Which configuration-management approach best supports that goal?
- During a quarterly WLAN security audit at city offices, which technique best discovers whether staff still share Personal PSK on whiteboards?
- A county security team schedules recurring checks of wireless controllers and captive portal servers. Which auditing procedure does that describe?
- A city IT governance review asks whether WLAN admin and guest-sponsor privileges are still appropriate. What auditing activity answers that question?
- A university campus that partners with the city for public events wants an annual wireless security assessment. What audit procedure fits, provided scope is clear?
- A municipal SOC suspects slow, low-and-slow abuse against wireless authentication. Which audit technique best looks for that pattern over time?
- After a city WLAN audit, findings must reach leadership for action. What reporting practice best supports remediation?
- A parks drone program requests a new video-backhaul SSID on the municipal WLAN. What security-lifecycle sequence should the WLAN security lead follow?
- A city change advisory board reviews a request to add an SSID that lacks documentation. What outcome reinforces proper WLAN security change management?
- Monitoring shows a municipal guest VLAN approaching firewall session limits during festival weeks. What load-observation response best protects secure service delivery?
- A bad ACL push on a city wireless controller blocks all EAP authentication for staff. How does configuration management help most in recovery?
- A county WLAN security program wants stronger ongoing assurance than any single check. Which quarterly approach best packages auditing procedures?
- Executives receive a municipal WLAN audit report that lists both open admin HTTP on controllers and a raw count of SSIDs. How should findings be presented?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by CWNP.