OSWP practice questions
OffSec · OSWP · 300 questions
Original practice questions for the OffSec Offensive Security Wireless Professional (OSWP) exam, covering IEEE 802.11 fundamentals, Wi-Fi encryption and security models, Linux wireless stack and toolchain, wireless reconnaissance and traffic analysis, WPA personal and credential recovery, WPS and rogue AP attack classes, WPA enterprise attack surfaces, and assessment workflow and reporting.
This course contains the use of artificial intelligence.
About the OSWP exam
- Exam fee
- $2749 USD
- Time allowed
- 4 hours
- Format
- Hands-on, proctored, performance-based: 3 wireless network scenarios in a private VPN lab; retrieve proof.txt from each target access point.
Exam details published by the vendor, checked 25 August 2026. Vendors change fees and formats without notice — confirm on the vendor's own page before you book.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
IEEE 802.11 & Wireless Network Fundamentals · 35 questions
- A city library IT lead asks what a BSSID uniquely identifies compared with an SSID name users see. What should the assessor explain?
- A parks department wonders why two APs can share one ESSID yet still be distinct on a wireless survey. What is the right explanation?
- A transit SOC asks whether naming only “channel 6” is enough to scope an authorized 802.11 capture. What judgment is sound?
- A school district asks why 2.4 GHz often feels more crowded than 5 GHz during a wireless survey. What is the best fundamentals answer?
- A municipal NOC asks what infrastructure mode means versus clients talking peer-to-peer. Which statement is accurate?
- A volunteer Wi-Fi team proposes an ad hoc IBSS for a city festival. What should an assessor flag about that choice versus AP-based service?
- A county assessor asks what association accomplishes after 802.11 authentication on a municipal WLAN. What is correct?
- A city help desk confuses 802.11 authentication with typing a username into a captive portal. How should the distinction be framed?
- A civic tech intern asks why management frames still matter to an assessor when user data frames are encrypted. What is the best answer?
- A water-utility engineer asks what beacons advertise that airodump-class tools commonly summarize. Which answer fits?
- A museum Wi-Fi lead asks why “hidden” SSIDs still show up in serious wireless assessments. What should be taught?
- A city CIO asks whether Wi-Fi “range” is a fixed meter count printed on an AP datasheet. What is the sound reply?
- A field tech asks why channel width (20/40/80 MHz) belongs in an assessment notes template. Why document it?
- A council chamber WLAN uses DFS channels. What awareness should the assessment note include?
- A library wants one SSID across floors so patrons can roam. What fundamentals point should the assessor keep straight?
- A stadium ops lead asks what an Association ID (AID) represents at a high level. Which statement is right?
- A SOC analyst asks why control frames (ACK/RTS/CTS class) differ in purpose from management frames. What is accurate?
- A city Wi-Fi policy draft claims all 802.11 traffic is “encrypted by default.” How should an assessor correct that myth?
- A municipal auditor asks what client isolation changes about station-to-station traffic on an AP. What is correct?
- A nonprofit asks whether Bluetooth and Wi-Fi are interchangeable for an 802.11 assessment scope. What should the lead reply?
- A campus NOC sees multiple overlapping BSSs on one channel. What co-channel awareness matters for performance and captures?
- A city asks why MAC addresses appear as BSSIDs and client STAs in recon output. What is the fundamentals reason?
- A temporary event WLAN enables only 2.4 GHz legacy rates for maximum device support. What tradeoff should planners accept?
- A help desk asks what a probe request is doing when a laptop is not yet connected to city Wi-Fi. What is correct?
- A security intern asks whether names like 802.11n, 802.11ac, and 802.11ax are encryption standards. What should the mentor say?
- A county fair vendor AP broadcasts a mesh/backhaul SSID and a separate client SSID from the same radio. For an authorized assessment, what must the scope statement do first?
- A municipal CISO asks what passive listening on Wi-Fi can typically observe without associating to the network. Which answer is most accurate?
- A network student on a city WLAN project treats the ESSID as if it were the VLAN ID. What distinction should the mentor emphasize?
- A city drone team's ground station uses a directional antenna for a control Wi-Fi link. What still holds true about 802.11 fundamentals?
- An auditor reviewing a municipal WLAN capture asks why Timing Synchronization Function (TSF) fields appear in deep wireless notes. What is the best explanation?
- A civic security lab compares AP-mode versus station-mode on the same USB Wi-Fi adapter. What should the team conclude about roles?
- A public works van provides crew tablets through a phone's mobile hotspot. How should an OSWP-minded assessor classify that hotspot's role?
- A university wireless team asks whether regulatory domain settings affect which channels are legal to use during an authorized campus assessment. What is correct?
- A city Wi-Fi coverage map labels a 'primary channel' on an 80 MHz BSS. What does that label mainly communicate?
- A mayor's office asks for a one-sentence difference between authentication and encryption on municipal Wi-Fi. Which statement is best?
Wi-Fi Encryption & Security Models · 35 questions
- A city policy still allows WEP 'for old scanners' on a warehouse SSID. Why should assessors treat WEP as insecure?
- A museum gift-shop AP is configured for TKIP-only WPA. What should the candidate recognize?
- A library asks what WPA2-Personal actually shares among authorized users on the staff SSID. What is accurate?
- A clinic wants per-user accountability on staff Wi-Fi so departed employees can be revoked individually. Which model best fits?
- A parks guest SSID is configured as open with no encryption and without OWE. What is the primary link-layer confidentiality concern?
- A city explores Opportunistic Wireless Encryption (OWE) for an 'enhanced open' guest network. What is OWE's core purpose at awareness depth?
- A SOC analyst asks what RSN information in 802.11 beacons roughly communicates about a municipal BSS. Which answer is best?
- A school enables WPA3 Transition Mode so older devices can still join. What risk-awareness point should the security lead keep in mind?
- A municipal CISO asks what SAE changes versus classic WPA2-PSK handshake assumptions. Which statement is most accurate?
- A vendor proposes WPA3-Enterprise 192-bit mode for a high-security municipal wing. When is that suite most appropriate?
- A help desk ticket claims an SSID is 'Enterprise' solely because the AP shows WPA2-AES. What clarification separates cipher from AKM?
- A county wireless architect asks why GCMP appears beside CCMP in newer WPA3 literature. What is the awareness-level answer?
- A city attorney asks whether choosing a long, complex passphrase makes WEP acceptable for a remaining legacy SSID. What is the correct guidance?
- A stadium operations SSID uses one WPA2-Personal PSK across thousands of staff devices. What shared-secret risk should leadership understand?
- A library WLAN team compares Protected Management Frames (PMF / 802.11w) set to optional versus required. What is PMF's main purpose?
- A civic Wi-Fi standard bans WPA-only networks on city access points. What baseline should the wireless assessor affirm?
- A municipal SOC sees both PSK and 802.1X AKMs advertised on the same RSN-capable city SSID. How should the assessor interpret that mix?
- A clinic asks whether MAC filtering can substitute for WPA2 or WPA3 on the care-team SSID. What should the assessor conclude?
- A city guest design uses per-user PSK (PPSK-class) instead of one café-style passphrase. What contrast should the assessor highlight versus classic single PSK?
- An auditor reviewing a municipal RSN profile asks what 'group cipher' versus 'pairwise cipher' means at a high level. What is the correct contrast?
- A nonprofit enables WEP on the main lobby SSID because inventory scanners 'only support it.' What priority should the authorized assessor recommend?
- A municipal RF policy asks when VPN-over-Wi-Fi is still relevant for city staff. What guidance fits an OSWP-style encryption assessment?
- A student claims 'WPA2 is unbreakable' after reading about AES-CCMP. What nuance should the municipal mentor emphasize for Personal mode?
- A city compares CCMP and TKIP on a dual-mode park AP that still serves modern clients. Which cipher preference should the assessor recommend when interoperability allows?
- A parks AP lists 'Open System authentication' alongside WPA2 in the controller summary. What does that combination mean for confidentiality?
- A county asks if hiding the SSID plus enabling WEP equals defense-in-depth for staff Wi-Fi. What should the assessor answer?
- A hospital WLAN profile requires Protected Management Frames (PMF). Why does healthcare Wi-Fi care about that control?
- A city explores SAE-PK and related modern WPA3 Personal enhancements at awareness depth. What should planners understand?
- A procurement RFP for civic APs says only 'AES encryption' without specifying WPA2 versus WPA3. What should security reviewers demand?
- A SOC asks what happens to confidentiality assumptions if someone already knows the municipal PSK and can capture traffic. What is the sound high-level answer?
- A library wants guest Wi-Fi that encrypts traffic without distributing a shared password. Which design class should the assessor point to?
- A city still runs mixed WEP plus WPA on one BSS for 'compatibility.' What should the assessor conclude about that baseline?
- An intern asks whether WPA3-Enterprise always requires EAP-TLS on city staff Wi-Fi. What is the accurate clarification?
- A municipal standard cites WPA3 Transition Mode themes versus stricter WPA3-only behaviors. What should assessors verify in the field?
- A CISO asks for the simplest correct upgrade path from café-style WPA2-PSK city Wi-Fi to something safer for staff. What direction should the assessor recommend?
Linux Wireless Stack, Drivers & Assessment Toolchain · 35 questions
- A city lab laptop cannot enter monitor mode during an authorized wireless assessment. What should the team investigate first?
- An assessor asks what mac80211 standardizes on modern Linux Wi-Fi stacks used in municipal labs. What is the best answer?
- A technician confuses managed mode with monitor mode during an authorized capture attempt on a county engagement. What distinction matters?
- Before enabling monitor mode, a municipal playbook says to check for interfering processes. Why does that step matter?
- A municipal assessor needs to know which airmon-ng action supports the aircrack-ng suite workflow. What is airmon-ng's purpose at a high level?
- A field kit for a municipal WLAN assessment lists airodump-ng, aireplay-ng, and aircrack-ng. How should the assessor map each tool to its primary role?
- A city asks how to identify a USB Wi-Fi adapter’s chipset when the plastic shell is unlabeled. What approach is most useful?
- An intern proposes using a pure client-mode USB dongle for deauthentication testing in a city lab. What capability concern should be raised?
- A municipal playbook mentions that the regulatory domain affects transmit power. What should assessors understand about that setting?
- A SOC wants SSH access to the exam Kali host while wireless tools keep running. What workflow practice best supports that need?
- After recovering a PSK in an authorized municipal lab, the next step is joining the SSID. Which statement best describes wpasupplicant-class tooling?
- A NetworkManager GUI fight with monitor mode frustrates a newbie on a city assessment laptop. What conflict class explains the pain?
- A city kit includes Alfa-class USB adapters for WLAN assessments. Why are external adapters commonly preferred in wireless labs?
- An assessor on a municipal engagement sees an interface named wlan0mon. How should that naming be interpreted?
- A city playbook says to put the card on the target channel before injection tests. Why does that matter?
- A municipal lab asks whether virtual machines always pass USB Wi-Fi adapters through cleanly. What is the realistic answer?
- A student confuses “aircrack-ng” the suite with “aircrack-ng” the cracker binary on a city training day. What clarification is correct?
- An assessor needs packet timestamps and frame-field detail beyond airodump-ng’s summary columns during a campus WLAN review. Which toolchain role fits?
- A city forbids installing random Git “auto Wi-Fi hack” scripts on assessment laptops. How does that policy align with good toolchain hygiene?
- A help desk asks whether enabling monitor mode by itself decrypts WPA2 traffic for a municipal investigation. What is accurate?
- A lab instruction for city assessors mentions rfkill blocking. What should they understand?
- A county kit documents driver module names for supported Wi-Fi cards. Why does that runbook exist?
- An assessor wants to confirm injection support with a non-destructive check before a timed municipal lab. What principle should guide that step?
- A student tries to capture in monitor mode while browsing the web on the same single Wi-Fi adapter. What limitation applies?
- A municipal standard requires documenting the adapter chipset in every wireless assessment report. What is the best reason for that requirement?
- A playbook lists iw and iwconfig-class commands for interface state on city assessment laptops. What role do those utilities play?
- An OffSec-style municipal lab bans wifite-class wrappers. What is the soundest toolchain-level reason?
- A city assessor dual-homes Ethernet for VPN backhaul and USB Wi-Fi for RF work. What lab networking benefit does that pattern provide?
- A newbie believes any Alfa-branded antenna guarantees wireless assessment success for the city kit. What correction is most accurate?
- A SOC asks when resetting a USB Wi-Fi adapter is reasonable during a stuck monitor session on a municipal engagement. What guidance fits?
- A city wireless lab must assess both 2.4 GHz and 5 GHz municipal SSIDs during one engagement. What hardware requirement best supports that dual-band work?
- An assessor documents firmware versions for municipal Wi-Fi USB dongles before monitor-mode work. Why does that firmware matter?
- A city uses Kali Linux as its wireless assessment distro. What is the most accurate view of Kali’s role?
- A municipal playbook stores wordlists on the assessment host. What statement best separates toolchain preparation from illegal targeting?
- After monitor-mode work on a civic assessment laptop, the technician must restore normal Wi-Fi to upload the report. What teardown step is most appropriate?
Wireless Reconnaissance & Traffic Analysis · 40 questions
- A city RoE allows only passive discovery in phase one of a municipal WLAN assessment. What best defines that passive wireless recon?
- An assessor reads ENC and AUTH columns on a municipal Wi-Fi survey. What should those fields primarily help distinguish?
- A library WLAN assessment must avoid targeting neighboring cafés that share the same channel. What scope discipline is required?
- A parks department survey shows many clients listed under one municipal BSSID. Why do those client lists matter to an assessor?
- A municipal team asks when active probe scanning is justified versus passive listening. What is the best guidance?
- A civic SOC wants a tool that inventories Wi-Fi devices over time with logging, not only a quick live dump glance. Which purpose class best fits?
- An assessor considers bettercap during a municipal wireless engagement. How should its assessment purpose class be described?
- A municipal capture file is huge. What analysis approach best focuses work on one target BSS?
- A city asks what signal power columns roughly indicate during a municipal Wi-Fi walkthrough. What is the best answer?
- An intern marks every open municipal-area network as 'in scope' because encryption shows OPN. What correction is required?
- A civic survey shows the same SSID on two channels with different BSSIDs. How should an assessor read that multi-AP ESS pattern?
- A hospital wing uses a hidden staff SSID that suppresses the name in beacons. How can authorized recon still discover it?
- An assessor needs to confirm whether a municipal BSS advertises WPA2 versus WPA3 from on-air frames. What should be examined?
- A city wants a channel utilization sense-check before wireless testing. Why do busy channels matter?
- A municipal capture includes EAPOL frames. What role should an assessor recognize for those frames?
- A municipal playbook prefers writing PCAP to disk during Wi-Fi surveys. What is the primary evidence benefit?
- An assessor sees MGT in an AUTH-class survey column for a city SSID. What does that indicator most likely suggest?
- A student continuously hops channels while trying to capture one municipal AP. What method correction is appropriate?
- A city asks whether GPS tagging of Wi-Fi surveys belongs in OSWP-style assessment skills. What is the balanced answer?
- An analyst uses tshark to extract certificate fields from an Enterprise municipal capture. What analysis purpose does that serve?
- A city library asks whether a wireless recon survey alone can prove that its staff Wi-Fi passphrase is weak. What should the assessor explain?
- During a parks department WLAN assessment, the team notes manufacturer OUIs derived from BSSIDs. What is the most accurate use of that observation?
- A municipal rules of engagement document bans deauthentication entirely during a wireless assessment. Which approach remains appropriate for observing handshake-class traffic?
- A city SOC plans to correlate wireless recon results with DHCP logs after a campus survey. What is the primary benefit of that multi-source approach?
- An assessor nearly targets a printer softAP after spotting an SSID that resembles the city's corporate ESS. What should happen before any active testing?
- A capture inside city hall shows repeated client probe requests for a home SSID. How should the assessor treat that finding?
- A timed municipal wireless assessment uses two wireless cards: one hopping for survey and one locked for capture. What is the main operational reason for that design?
- A municipal wireless report requires screenshots of survey output before describing later testing. Why include those recon screenshots?
- An intern enables verbose frame injection during early recon 'to be thorough' on a live city WLAN. What guidance should the lead give?
- A new assessor opens bettercap and feels overwhelmed by the module list on a municipal engagement. What is the professional approach?
- A city asks what Kismet adds beyond simply listing nearby SSIDs during wireless monitoring. What is the best answer?
- During analysis of an authorized municipal capture, an assessor filters Wireshark for EAP identity strings. What can those fields usefully reveal?
- A campus survey discovers mesh backhaul SSIDs alongside user-facing city Wi-Fi names. How should those backhaul SSIDs be handled?
- A student on a city lab engagement saves only ASCII terminal logs and discards PCAP files. Why is that a problem for wireless evidence?
- A municipal red team wants a quick map of which access points advertise WPS capability before deeper testing. Which tool-purpose class fits that recon goal?
- While surveying a county WLAN, an assessor starts deep-diving DTIM and beacon interval quirks before recording crypto mode or clients. What prioritization correction fits OSWP-style goals?
- At a city special-event venue, recon shows access points still using vendor-default SSID naming patterns. What should the assessor conclude from that observation?
- An assessor reviews a capture intended for a specific city AP and finds handshake and data frames of interest missing. The radio was tuned to a different channel than the AP. What explains the gap?
- An analyst labels both 'LAB-CITYWIFI' and 'CityWifi' as the same municipal target without comparing BSSIDs. What is the correct challenge to that assumption?
- Before any active wireless testing on a municipal engagement, a recon brief asks which survey facts should be recorded at minimum. Which answer best matches that checklist?
WPA Personal & Credential Recovery Concepts · 45 questions
- In a city wireless lab, staff ask what the WPA2-Personal 4-way handshake is meant to prove between the AP and a client. What is the best explanation?
- An assessor captured only two EAPOL messages toward a municipal WPA2-Personal target. What should they conclude about offline PSK testing readiness?
- A municipal RoE allows a brief deauthentication in a lab to force reauthentication on a WPA2-Personal SSID. What is the purpose of that action class?
- A student wants to perform classic WPA2-PSK offline credential recovery without any client ever connecting to the city lab AP. What dependency should the instructor emphasize?
- A county security lead asks why weak Wi-Fi passphrases often fall after a WPA2-Personal handshake is obtained in an authorized assessment. What is the core reason?
- A city wireless assessment team compares recovering a WPA2-PSK passphrase with aircrack-ng on CPU versus hashcat on a GPU lab box. At judgment level, what difference matters most?
- An assessor evaluating a municipal WPA2-Personal capture considers adding John the Ripper to the toolchain. What purpose class does John the Ripper fill here?
- Older municipal wireless lab notes mention coWPAtty next to WPA-PSK dictionary practice. What historical purpose should the assessor assign to coWPAtty?
- A legacy PEN-210 outline lists Pyrit among WPA-PSK acceleration tools. How should a city assessor treat Pyrit today at the concept level?
- A municipal passphrase policy sets staff IoT Wi-Fi secrets to patterns like SeasonYear!. What offline-attack outcome should the assessor expect?
- An assessor converts a municipal .cap handshake file into a hashcat-ready container before GPU cracking. What concept does that step illustrate?
- A city asks whether WPA3-SAE staff SSIDs are equally exposed to the classic capture-then-offline-dictionary path used against WPA2-PSK. What is the best conceptual answer?
- After a successful authorized lab recovery of a WPA2-PSK, the municipal engagement defines success as joining the AP and fetching an intranet proof file. What success-criteria class does that describe?
- A student aims aircrack at the wrong ESSID inside a multi-SSID municipal capture. What process lesson applies?
- A municipal rules of engagement forbid deauthentication during a WPA2-Personal assessment. How should the team collect handshake material?
- An analyst has a valid municipal WPA2 handshake, yet a huge wordlist returns no passphrase. What limit should be considered first?
- A city uses a unique 20-character random PSK on a staff IoT SSID. What residual risk class remains even when offline guessing looks impractical?
- In a municipal wireless lab, what does the PMK represent relative to the WPA-Personal passphrase?
- Lab notes discuss the PTK after a WPA handshake on a city AP. What role does the PTK play?
- A municipal WLAN review asks what group keys (GTK) protect on a WPA2 network. What is the correct class?
- A municipal red team asks whether capturing ever more IVs helps WPA2-PSK the way old WEP myths suggested. What correction applies?
- Community notes mention PMKID-class techniques against some WPA2-Personal networks. How should a city assessor treat PMKID at awareness level?
- A city asks when expanding the wordlist or rules beats switching cracking tools during a WPA2-PSK attempt. What judgment is soundest?
- An assessor documents the exact wordlist and rules used while recovering a municipal guest PSK. Why does that reporting detail matter?
- A student confuses online password guessing against a live municipal AP with offline handshake cracking. What distinction should stick?
- A clinic IoT SSID uses the device serial number printed on the badge as its WPA2-PSK. How should an assessor classify that choice?
- In a timed municipal wireless lab, a strong PSK is unlikely to fall to a rockyou-class list. What pivot judgment is appropriate?
- A municipal standard requires WPA3-Personal (SAE) for temporary guest pop-up SSIDs. What security benefit is the standard mainly buying versus legacy WPA2-PSK guests?
- Before investing GPU time, an assessor reviews a municipal capture in Wireshark to validate handshake quality. What should that QA step confirm?
- A city asks whether mishandled EAPOL message order or incomplete frames can produce false 'bad handshake' errors in cracking tools. What process guidance is best?
- A municipal WLAN lab builds a custom dictionary of local street names and civic landmarks for an authorized guest-PSK recovery test. Why can that targeted list outperform a generic rockyou-style dump?
- After an authorized city guest-Wi-Fi assessment recovers a weak PSK, an intern wants to paste the passphrase into a public Discord channel for 'study notes.' What is the correct handling?
- An authorized capture of a municipal WPA2-PSK SSID includes complete 4-way handshakes from several staff laptops. For offline passphrase testing against that shared PSK, what is generally true?
- A city CISO asks why encrypting the assessor's generic wordlist on disk matters less than locking down cracked guest PSKs and client identifiers from the engagement. What is the best answer?
- A municipal IoT SSID uses a 63-character high-entropy random WPA2-PSK. In an exam-like timed dictionary assessment, what expectation is most realistic?
- During an authorized county Wi-Fi assessment, an assessor considers uploading captured handshakes to a third-party cloud cracking service for speed. What concern should stop that move without explicit approval?
- A student claims aircrack-class dictionary testing 'attacks the router CPU' to recover a municipal guest PSK. What correction is most accurate?
- A municipal IoT SSID shares one WPA2-PSK across dozens of sensors and rotates that passphrase quarterly. What primary security benefit does regular rotation provide?
- Lab recovery shows the correct municipal guest passphrase, yet the assessor's station still fails to associate. What should be checked first among common mismatches?
- A city workshop asks whether capturing a WPA handshake and attempting recovery against a neighbor's home Wi-Fi without permission is acceptable practice for OSWP-style learning. What is the correct stance?
- An assessor expands a short municipal base wordlist with rules and masks that append years, seasons, and civic abbreviations. What problem class does that technique address?
- A WPA2-PSK municipal kiosk AP shows no associated clients overnight, and the rules of engagement forbid deauthentication. Why might handshake-based recovery be blocked until later?
- A draft municipal report states 'WPA2 is broken' after offline recovery of a weak guest passphrase. How should the finding be reframed?
- Before a parks-department WLAN assessment, the city wants preventive guidance on passphrase strength for remaining WPA2-Personal SSIDs. What recommendation best reduces typical offline dictionary wins?
- An OffSec-style wireless practice workflow states that when a dictionary is required, only default Kali wordlists may be used. How should the assessor plan?
WPS, Rogue AP & Captive Portal Attack Classes · 55 questions
- A city AP still has WPS enabled 'for easy onboarding' on a staff SSID. Why do authorized assessors typically flag that setting?
- A municipal technician asks what WPS was originally intended to solve for consumers. What is the best description?
- In an authorized WPS assessment, an assessor contrasts online PIN attempt classes with offline pixie-class testing. What is the essential distinction?
- A wash-class survey of municipal APs marks several WPS-capable devices as locked. How should an assessor interpret that status for online PIN attack feasibility?
- A county asks for the simplest remediation when WPS is enabled on APs but is not required for onboarding. What should be recommended?
- A student argues that WPS risks only matter on legacy WEP networks. What correction should an instructor give?
- Study notes mention a reaver-class tool during WPS modules. Without providing a command recipe, what purpose class should a candidate remember?
- Inventory shows a city IoT SSID with WPS push-button configuration (PBC) enabled. What awareness point should the assessment highlight?
- An assessor documents vendor-specific WPS implementation bugs as a finding class on mixed municipal hardware. What reporting principle applies?
- A library floor walk finds a printer softAP advertising WPS while corporate controllers look clean. Why does that matter for Domain 6 inventory?
- A municipal IT lead proposes a rogue AP during an authorized wireless assessment to see whether staff join lookalike SSIDs. What goal best defines that evil-twin class of testing?
- A municipal blue team asks how client devices typically choose among duplicate SSIDs when a rogue AP appears nearby. Which theme best explains that preference behavior?
- During a city wireless lab, an assessor mentions hostapd as a building block for a controlled rogue AP. What purpose does hostapd serve in that context?
- hostapd-mana appears in Enterprise and rogue-AP coursework for a municipal purple-team lab. What mana-class purpose should the assessor state—without diving into configs?
- A county training session discusses Karma-style responses to client probe requests. At awareness depth, what does that Karma-class behavior do?
- A city SOC detects an unauthorized AP in a lobby. For OSWP-style literacy, how should detection work be framed relative to offensive rogue-AP study?
- An assessor clones a municipal guest open SSID for a controlled captive-portal test under RoE. How should that scenario be classified?
- A civic Wi-Fi captive portal asks users for an email address before granting Internet. What function does that portal primarily provide?
- A student claims HTTPS captive portals cannot be spoofed on a rogue network the assessor fully controls. What nuance about trust on that path is most accurate?
- DNS redirection concepts appear in a city's captive-portal lab. Why does DNS matter for portal behavior—without needing firewall recipes?
- A municipal assessment's rules of engagement forbid credential-harvesting portals. What should the assessor do regarding those techniques on that engagement?
- An evil twin in an authorized conference-room test advertises a stronger signal than the real municipal AP. What placement awareness should the assessor take away?
- A city asks whether client MAC randomization stops all evil-twin risks. What is the most accurate limit of that control?
- On an authorized rogue open AP, a fake captive portal prompts staff for a 'Wi-Fi password' field. How should that hybrid technique class be described?
- A municipal blue team maintains known-SSID and BSSID inventories to spot rogues. What defensive value does that inventory provide relative to offense literacy?
- An assessor must choose between WPS testing and rogue-AP testing against a locked-down municipal WPA3-SAE network with WPS disabled. Which selection principle applies?
- A stadium warns event staff about lookalike SSIDs during large events. As remediation when technical controls are incomplete, what does that user-awareness step primarily reduce?
- A city wireless lab documents both the fake portal page and recovered passphrase artifacts as evidence. Why keep those artifacts for the report?
- A city guest network already runs a legitimate captive portal. What testing-impact caution should guide an assessor's portal-related work?
- An intern wants to use wifiphisher-class automation on an OSWP-style exam-culture question for the city's practice drills. What policy stance should leadership reinforce?
- A municipal AP shows WPS enabled only on the 2.4 GHz radio while 5 GHz appears disabled for WPS. What configuration mistake does that partial state illustrate?
- A rogue AP offers open authentication while the real municipal network is WPA2. Why might some clients still join the weaker lookalike?
- A county asks whether Protected Management Frames (PMF) alone stop all evil-twin risks. What limitation is most accurate?
- An assessor reviewing wireless scans sees WPS states such as 'configured' versus 'not configured.' What should those flags guide?
- During an authorized purple-team exercise, a city hall lobby hosts a purpose-built free Wi-Fi pineapple-class rogue kit. What client-attraction framing should assessors emphasize?
- A civic assessment RoE allows a captive-portal awareness test that visually clones the municipal guest login theme. What ethics constraint still applies?
- During an authorized municipal WPS PIN test, SIEM alerts fire from AP logs that show repeated WPS authentication failures. What assessment insight does that highlight?
- A city AP aggressively lockouts online WPS PIN attempts. At concept level, how should an authorized assessor adapt?
- A library kiosk is configured to auto-join the strongest SSID named LibraryGuest. Why does that increase evil-twin risk?
- A city asks for architectural remediation against rogue APs that goes beyond user awareness training. Which theme set best fits?
- In a municipal captive-portal lab on a rogue AP host, why is an HTTP (web) service typically required?
- Why do authorized rogue-AP labs typically include DHCP service for victim clients?
- An assessor must choose between attempting WPA2-PSK credential recovery and deploying a captive-portal rogue against a conference guest SSID. What should drive the choice?
- A municipal policy bans personal hotspots that reuse or closely collide with corporate SSID names. What risk is that policy trying to reduce?
- A municipal wireless report marks a WPS finding critical because successful WPS abuse reveals the network PSK. What severity framing is that using?
- A city wants to keep push-button WPS available only when an admin is physically present. How should an OSWP-style assessment view that control?
- An authorized evil twin targets clients that expect a PSK network. What handshake-related outcome can that rogue class induce?
- A captive-portal lab records browser and OS captive-detection endpoint probes. Why do assessors care about those probes?
- A nonprofit asks whether an open guest SSID plus captive portal is secure enough for staff workflows that handle PII. What is the sound OSWP-aligned answer?
- After an authorized municipal rogue-AP test window ends, what engagement hygiene is required?
- A wash-class scan shows WPS version and manufacturer metadata on a city AP. What is the correct interpretation before claiming a finding?
- A city council demo accidentally leaves a lab rogue SSID running overnight in the building. What lesson should the after-action note emphasize?
- A municipal wireless assessment report recommends WIPS signatures tuned for evil-twin detection. Why include that defensive advice?
- A student proposes RF jamming to force municipal clients onto a lab rogue AP. What is the correct OSWP-aligned response?
- A municipal AP presents WPS enabled, a weak open guest portal, and a strong WPA3-SAE staff SSID. Within RoE, which surface should the assessor prioritize first?
WPA Enterprise Attack Surface Concepts · 35 questions
- Recon against a city staff SSID shows 802.1X / MGT-class authentication rather than PSK. What does that imply for the assessment approach?
- A municipal architecture diagram lists 802.1X roles as supplicant, authenticator, and authentication server. How do those map on a typical staff WLAN?
- A clinic staff SSID uses PEAP with MSCHAPv2 as the inner method. What weakness class should assessors recognize at concept level?
- A county mandates EAP-TLS for staff laptops on the corporate SSID. What strength class does that requirement target?
- City employees routinely click through Wi-Fi server certificate warnings on their staff SSID. How does that behavior affect Enterprise evil-twin risk?
- An assessor studies a rogue Enterprise AP concept that presents a familiar municipal SSID. What attack surface does that scenario primarily define?
- FreeRADIUS appears in municipal lab notes for authenticating test clients on an Enterprise SSID. What is its AAA purpose in that design?
- asleap-class tooling is named in a county wireless assessment inventory for MSCHAPv2 material. What purpose should the item record—without describing exploit steps?
- A capture on a city Enterprise SSID shows EAP identities such as [email protected]. What recon lesson should the assessor take away?
- A city asks whether a strong Active Directory password alone makes PEAP safe against evil twins if users skip server certificate checks. What is the right risk answer?
- EAP-TTLS is compared with PEAP at awareness depth for a municipal RFP. What fair contrast should the wireless lead document?
- A hospital WLAN disables user password prompts by deploying machine certificates for Enterprise access. What passwordless theme does that change emphasize?
- An assessor extracts a server certificate from a municipal Enterprise capture to study issuer fields in a lab. What conceptual awareness is appropriate—without forge recipes?
- A city SOC asks why WPA-Enterprise is preferred for staff accountability compared with a shared PSK. What benefits should the brief highlight?
- A university WLAN still allows EAP-MD5 on an older staff profile. What awareness finding should the assessor raise?
- A city segments the staff Enterprise SSID from an open guest network. What architecture hygiene does that separation primarily enforce?
- An authorized evil-twin lab against a municipal PEAP deployment captures MSCHAPv2 challenge/response material. How should that material be classified?
- A municipal identity provider outage suddenly breaks staff Wi-Fi logins on the Enterprise SSID. What operational dependency does that incident illustrate?
- A student claims Enterprise Wi-Fi means an un-capturable handshake compared with WPA-Personal. What nuance should the instructor teach?
- A city uses dynamic VLAN assignment via RADIUS after successful staff EAP. What post-authentication capability does that demonstrate?
- An assessor documents required client trust-store settings for municipal Enterprise laptops. What hardening guidance belongs in that note?
- A PEAP deployment for county staff omits the validate server certificate option on endpoints. What misconfiguration class does that create?
- A county compares password-spray risk on Enterprise Wi-Fi usernames discovered via EAP. What chained risk should the brief note?
- A lab connects with wpasupplicant using PEAP settings after obtaining authorized credentials. What validation class does a successful join represent?
- A city asks whether adopting WPA3-Enterprise changes everything about PEAP risks overnight. What balanced answer should advisors give?
- An auditor wants proof that municipal staff cannot join a rogue AP broadcasting the corporate SSID. What assurance approach fits?
- A help desk resets Enterprise Wi-Fi passwords verbally in an open county office. What operational weakness near Enterprise controls does that illustrate?
- A RADIUS shared secret between a municipal wireless controller and the AAA server is trivial to guess. What infrastructure hardening issue should be raised?
- A municipal laptop Wi-Fi profile uses incorrect outer identity privacy settings during EAP. What identity-privacy awareness should IT apply?
- An assessor sees TLS alerts during EAP on a city Enterprise SSID. How should those clues be interpreted under rules of engagement?
- A city WLAN team wonders whether Fast BSS Transition (802.11r) can run with WPA2-Enterprise on staff SSIDs, or whether Enterprise forces them to drop roaming helpers. What awareness-level judgment should the assessor give?
- A municipal wireless report recommends replacing PEAP-MSCHAPv2 on the county staff SSID with EAP-TLS and enforcing certificate validation. What makes that remediation high quality for Enterprise Wi-Fi risk?
- A student on a city internship proposes capturing Enterprise Wi-Fi traffic and “just running aircrack like PSK.” What category error should the mentor correct?
- A city guest portal rides open/captive access while staff use WPA2-Enterprise on the same AP hardware. What multi-SSID security judgment matters most for assessment and design advice?
- During an authorized OffSec-style timed wireless scenario, recon shows AUTH/MGT rather than PSK on the target SSID. Which selection judgment should guide the candidate?
Assessment Workflow, Reporting & Safe Practice · 20 questions
- A mayor asks a consultant to “quickly test the courthouse Wi-Fi” with no written authorization from the system owner. What should the consultant do?
- An OSWP-style lab presents three wireless scenarios, but the exam model activates only one at a time via the control panel. What workflow judgment is correct?
- A timed OSWP-style exam names a mandatory wireless scenario in the control panel. How should the candidate prioritize for a passing outcome?
- A candidate recovers wireless keys in an OSWP-style lab but forgets to submit proof contents in the exam control panel before lab time expires. What failure mode does that illustrate?
- For each completed OSWP-style scenario, what minimum evidence class should appear in the professional report besides narrative steps?
- A municipal wireless assessment report lists trophies but omits commands and outputs a peer could follow. What scoring or quality risk should the author expect?
- A candidate wants to run wifite to save time on an OffSec wireless exam culture question. What policy judgment is correct?
- During a proctored OffSec wireless exam, a candidate proposes asking an AI chatbot for live attack hints. What is the correct policy response?
- After OSWP-style lab time ends, the candidate has a limited window to upload a PDF report archived as a .7z with a strict filename pattern. What submission hygiene matters most?
- A municipal client asks that the wireless assessment report include remediation alongside offensive proofs. What balanced reporting practice should the consultant follow?
- A candidate burns three hours on one stubborn OSWP-style scenario and risks missing the pass rule. What time-management judgment applies?
- Rules of engagement for a city production WLAN window ban deauthentication and rogue AP deployment even though coursework taught those technique classes. What should the assessor do?
- A report for an OSWP-style attempt includes another student’s screenshots of key recovery. How should that be treated?
- A city engagement requires stopping wireless tests if production availability collapses beyond agreed thresholds. What safe-practice awareness does that encode?
- An assessor stores cracked municipal PSKs from an authorized engagement in an unencrypted public repository. What data-handling failure does that represent?
- A candidate finishes two OSWP-style scenarios including the mandatory one but uploads the report after the allowed post-exam window. What deadline risk applies?
- A municipal CISO wants weekly evil-twin tests in the public lobby without change control or user communication. What process pushback is appropriate?
- A city wireless assessment template includes an executive summary and a technical appendix. What audience-layering purpose does that structure serve?
- A student asks whether earning OSWP means annual retesting because the credential expires like some other OffSec certifications. What validity awareness is accurate per published OffSec FAQ themes?
- A closing prep brief asks what “similar-concept MCQ” practice should never replace for OSWP candidates. What is the right boundary?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by Offensive Security.