Vulnerabilities, Threats, and Attacks
CWSP · 90 questions
- A new AP firmware advisory appears in a CVE feed for the city's campus WLAN vendor. What is the most appropriate first use of that information source?
- The vendor PSIRT publishes a remote code execution advisory for the municipal WLAN controller, but staff only read informal news blogs. Which guidance is best?
- An IoT badge reader used at county building doors has a published CVE in its Wi-Fi module. How should WLAN vulnerability scope treat that finding?
- After a major WPA2-class vulnerability headline, city security asks whether municipal Wi-Fi is affected. What should the CWSP do next?
- A regional library consortium runs many APs and controllers but has no process to watch CVE or vendor advisories for WLAN gear. What gap should be called out?
- Open-source RADIUS used for 802.1X on the transit-authority WLAN has a published CVE. How should vulnerability tracking treat that system?
- A CVE for a city hall AP requires physical console access to exploit. After recording the CVE, how should impact judgment differ from a remote wireless exploit?
- A critical remote exploit targets internet-exposed cloud WLAN dashboards used by the municipality, while another AP bug is local-only on an isolated management VLAN. How should relative risk be rated?
- A guest SSID isolation failure on city visitor Wi-Fi could expose the payment VLAN used by municipal cashiers. What should dominate the impact assessment?
- A deauthentication flood hits the city's VoWLAN used by public-safety and facilities radios. How should impact primarily be framed?
- An unpatched WEP pop-up kiosk on the county fairgrounds seems low risk until engineers discover it bridges onto the corporate WLAN. What does impact analysis require?
- A controller vulnerability for the municipal WLAN requires valid administrator credentials before it can be exploited. How should that affect remote risk relative to an unauthenticated wireless exploit?
- The same AP CVE appears on a closed city IT lab WLAN and on production stadium Wi-Fi serving tens of thousands of fans. How should risk differ?
- During a city risk meeting, staff treat a high CVSS number as the complete WLAN risk rating and ignore likelihood and local business impact. What correction is needed?
- Municipal policy requires WPA3, but an SSID still allows TKIP. What mitigation best addresses that finding?
- A vendor releases a patch for a critical CVE on the city's WLAN controllers. What is the appropriate mitigation when a fix exists?
- A compromised municipal AP cannot be patched yet. What mitigation should the CWSP select in the meantime?
- After suspicious 802.1X authentication failures on the courthouse WLAN, engineers skip logs and packet review. What mitigation and verification step is missing?
- Auditors find an open management SSID on the city's WLAN that violates written security policy. What is the primary mitigation?
- A zero-day affects AP OS images on the municipal mesh with no vendor patch yet, but compensating WIPS signatures are available. What mitigation approach fits best?
- A county facilities closet reveals a compromised rogue access point plugged into a live switch port on the municipal staff VLAN. Besides removing the device, which mitigation best contains the wired attachment risk?
- A city WLAN vendor releases a fixed AP code train for a known vulnerability, but the municipal change window is next week. What mitigation approach best fits until the upgrade can run?
- Config audits show drift re-enabled cleartext HTTP administration on several library-branch access points that policy requires to use HTTPS-only management. What remediation best restores policy conformance?
- An attacker outside a municipal community center records unprotected 802.11 frames on the city’s open public cafe-style SSID. Which threat does this scenario primarily illustrate?
- Workers near city hall associate to a fake access point that advertises the corporate municipal SSID and presents a look-alike login to harvest credentials. Which attack pattern best describes this?
- A researcher captures a WPA2-Personal 4-way handshake from a parks-department shared staff SSID that uses a short dictionary passphrase, then runs an offline password guess against that handshake. Which WLAN attack does this demonstrate?
- County employees receive SMS messages saying “update your Wi-Fi password” with a link to a fake portal that asks for municipal network credentials. Which attack category best fits?
- During a civic-center incident review, analysts see bursts of deauthentication frames that force laptops to reconnect while a nearby adversary captures handshakes. What is the best characterization of this technique?
- At a downtown transit hub, a malicious responder answers preferred-network probes from city tablets for popular SSIDs the devices remember, luring them to associate. Which attack behavior is this?
- A shared parks-and-recreation staff PSK for a WPA2-Personal SSID appears on a public paste site. Beyond immediate key rotation, which risk statement is most accurate?
- An insider at a municipal court annex runs a soft AP on a laptop that bridges the guest SSID segment onto the staff VLAN. Which attack path does this primarily represent?
- During a city council Wi-Fi outage drill, clients see dozens of rapidly appearing fake SSIDs and struggle to find the legitimate municipal network. Which attack best matches this symptom?
- A field locker-room AP in a city recreation center still has WPS PIN enrollment enabled contrary to hardening standards. Which threat should security staff highlight?
- A spear-phishing campaign against finance staff at city hall installs a malicious wireless profile that prefers an attacker-controlled SSID. How does this social-engineering outcome enable further WLAN compromise?
- Municipal WIPS alerts on an access point advertising the corporate city SSID with an unknown BSSID and fingerprint not in the authorized inventory. What should analysts conclude they have detected?
- Protocol analysis for a transit-yard WLAN shows unusual deauthentication spikes that correlate with sudden client drops. Which detection conclusion is most appropriate?
- The city’s SIEM correlates repeated RADIUS rejects from one wireless MAC with physical door-badge misuse events for the same employee badge ID. What detection capability does this illustrate?
- Library patrons and remote staff report look-alike captive portals when off campus, prompting the security desk to open tickets. How do these reports function in WLAN attack detection?
- Security reviewers note that offline PSK cracking leaves little live RF noise on the city WLAN. Where should detection effort focus for this risk?
- Integrated AP sensors in a municipal conference wing flag an ad-hoc soft AP running on an attendee laptop. What has the WLAN security system most likely detected?
- A protocol analyzer at the utilities operations center shows a supposed enterprise staff SSID offering open authentication instead of 802.1X. What eavesdropping-related condition has been detected?
- An overlay WIPS deployment places a rogue transmitter on the city-hall floor map using RF location. Which detection capability is being demonstrated?
- Traffic analysis on the municipal guest VLAN shows scanning probes toward staff subnets that policy says must remain isolated. What does this monitoring result indicate?
- The wireless security lead for a county clinic WLAN must mitigate eavesdropping against sensitive traffic. Which mitigation best matches CWSP guidance?
- City IT wants to mitigate evil-twin MITM against the staff enterprise SSID used in civic offices. Which combination best aligns with recommended mitigations?
- A county parks department shares one WPA2-Personal passphrase across maintenance tablets. After a staff laptop is stolen with the passphrase saved, offline cracking of captured handshakes becomes a realistic risk. Which mitigation best reduces that cracking exposure going forward?
- City employees keep entering civic credentials into look-alike captive portals while traveling. Which WLAN phishing mitigation best reduces successful credential theft?
- A municipal library’s public SSID experiences repeated client disconnect storms consistent with spoofed deauthentication frames. Which mitigation pair best reduces impact?
- A town hall WLAN still has Wi-Fi Protected Setup enabled on corridor APs used for guest and staff onboarding. Which mitigation best addresses enrollment PIN attacks?
- County free Wi-Fi in the permit office allows guest devices to reach each other on the same SSID. Which mitigation best reduces client-to-client attacks on that guest WLAN?
- After a transit-yard shared PSK appears in a public paste site, which remediation best restores WLAN credential hygiene?
- WIPS locates a rogue AP bridged onto a city-hall switch closet and advertising a look-alike staff SSID. Per policy, which containment approach is most appropriate?
- A warehouse barcode SSID for a municipal supply depot still uses WEP. What should the CWSP conclude about that security solution?
- A city conference-room transition SSID still negotiates TKIP for older laptops. How should the security engineer treat TKIP?
- Marketing Wi-Fi for a civic festival is still labeled only 'WPA' on the controller profile, not WPA2 or WPA3. What is the correct assessment?
- During a county WLAN architecture review, RC4 appears in a cipher-suite discussion for air encryption. How should RC4 be classified for Wi-Fi security?
- Vendor default profiles on city APs include a 'WPA/WPA2 mixed' mode that still enables TKIP for compatibility. How should that default be treated?
- An auditor asks why the city’s staff SSID uses CCMP instead of TKIP. What is the best explanation?
- A museum exhibit controller only supports WEP. A technician suggests hiding the SSID so WEP is 'safe enough.' What is the correct mitigation approach?
- Before a WLAN penetration test of county buildings, what must the team establish first?
- During a civic WLAN security assessment, testers compile SSID inventories, AP locations, and client device types before launching active attack techniques. Which phase does this describe?
- Testers enumerate encryption modes on city SSIDs and probe open management ports on wireless controllers before any exploitation attempts. Which pen-test phase is this?
- During the attack phase of a school-district WLAN test, which practice is correct?
- After WLAN security testing at a county clinic, what documentation practice is required?
- An auditor must inspect EAPOL handshake exchanges on a city staff SSID. Which tool class is the appropriate selection for that task?
- A municipal IT team must verify encryption and authentication modes on every civic SSID before an annual review. Which approach best fits that goal?
- When are Kali Linux wireless toolkits appropriate in a city WLAN security program?
- A county tester needs reliable monitor-mode captures outdoors near a water-treatment plant WLAN. How should hardware be selected?
- Which project-documentation practice best supports a repeatable municipal WLAN security test?
- A helpful intern begins scanning and attempting associations against city SSIDs without written approval, calling the activity a 'security test.' What is the correct CWSP assessment?
- A city WLAN team sees WIPS alerts, RADIUS rejects, and switchport flapping but they live in separate consoles. Which monitoring approach best correlates those events centrally?
- A county wants dedicated RF security coverage that keeps watching even if serving access points are busy or misconfigured. Which WIPS model fits?
- A municipal IT director asks how integrated WIPS differs from overlay for city hall Wi-Fi. What is the accurate tradeoff?
- A city hosts a weekend pop-up civic festival with temporary Wi-Fi and needs short-term RF security watching without permanent sensors. Which approach fits?
- A multi-campus school district must watch WLAN security at every site. Why choose distributed collectors over a single central poller alone?
- During a library WLAN redesign, staff confuse WIDS with WIPS. Which statement correctly separates the roles?
- A mayor asks why the city still funds ongoing WLAN monitoring after writing a strong wireless policy. What is the best justification?
- A transit agency already runs overlay WIPS. How should RF security events become actionable operations tickets with identity and network context?
- Before rating WLAN risks for a civic data center Wi-Fi plant, what asset-management step must come first?
- A hospital WLAN risk review omitted wireless IoT infusion pumps from the asset list. Why does that understate risk?
- A hospital SSID misconfiguration could expose clinical workflows. How should the WLAN risk rating be formed?
- Two WLAN flaws have similar impact: one needs rare physical console access; the other is a common remote wireless exploit. How should ratings differ?
- A cracked guest bridge could expose cardholder data on a city-run retail kiosk WLAN. What should loss expectancy emphasize?
- Stadium Wi-Fi planners compare one sold-out weekend outage to a year of repeated rogue-AP incidents. Which loss-expectancy framing is sound?
- A county WLAN risk plan must sequence remediation. Which priority order best matches critical deprecated crypto and monitoring gaps?
- A legacy barcode-scanner SSID cannot move off weak crypto this quarter. What must the WLAN risk plan document?
- Why should asset classification treat guest APs differently from payment-terminal APs in a civic arena?
- In a city risk workshop, analysts fear false precision from made-up percentages. How should they still produce usable WLAN risk ratings?
- Estimating loss expectancy for a city council Wi-Fi breach should include which loss categories?
- A draft WLAN risk plan proposes to 'accept WEP forever' with no isolation and no executive signature. What should the plan require instead?