WPA Enterprise Attack Surface Concepts
OSWP · 35 questions
- Recon against a city staff SSID shows 802.1X / MGT-class authentication rather than PSK. What does that imply for the assessment approach?
- A municipal architecture diagram lists 802.1X roles as supplicant, authenticator, and authentication server. How do those map on a typical staff WLAN?
- A clinic staff SSID uses PEAP with MSCHAPv2 as the inner method. What weakness class should assessors recognize at concept level?
- A county mandates EAP-TLS for staff laptops on the corporate SSID. What strength class does that requirement target?
- City employees routinely click through Wi-Fi server certificate warnings on their staff SSID. How does that behavior affect Enterprise evil-twin risk?
- An assessor studies a rogue Enterprise AP concept that presents a familiar municipal SSID. What attack surface does that scenario primarily define?
- FreeRADIUS appears in municipal lab notes for authenticating test clients on an Enterprise SSID. What is its AAA purpose in that design?
- asleap-class tooling is named in a county wireless assessment inventory for MSCHAPv2 material. What purpose should the item record—without describing exploit steps?
- A capture on a city Enterprise SSID shows EAP identities such as [email protected]. What recon lesson should the assessor take away?
- A city asks whether a strong Active Directory password alone makes PEAP safe against evil twins if users skip server certificate checks. What is the right risk answer?
- EAP-TTLS is compared with PEAP at awareness depth for a municipal RFP. What fair contrast should the wireless lead document?
- A hospital WLAN disables user password prompts by deploying machine certificates for Enterprise access. What passwordless theme does that change emphasize?
- An assessor extracts a server certificate from a municipal Enterprise capture to study issuer fields in a lab. What conceptual awareness is appropriate—without forge recipes?
- A city SOC asks why WPA-Enterprise is preferred for staff accountability compared with a shared PSK. What benefits should the brief highlight?
- A university WLAN still allows EAP-MD5 on an older staff profile. What awareness finding should the assessor raise?
- A city segments the staff Enterprise SSID from an open guest network. What architecture hygiene does that separation primarily enforce?
- An authorized evil-twin lab against a municipal PEAP deployment captures MSCHAPv2 challenge/response material. How should that material be classified?
- A municipal identity provider outage suddenly breaks staff Wi-Fi logins on the Enterprise SSID. What operational dependency does that incident illustrate?
- A student claims Enterprise Wi-Fi means an un-capturable handshake compared with WPA-Personal. What nuance should the instructor teach?
- A city uses dynamic VLAN assignment via RADIUS after successful staff EAP. What post-authentication capability does that demonstrate?
- An assessor documents required client trust-store settings for municipal Enterprise laptops. What hardening guidance belongs in that note?
- A PEAP deployment for county staff omits the validate server certificate option on endpoints. What misconfiguration class does that create?
- A county compares password-spray risk on Enterprise Wi-Fi usernames discovered via EAP. What chained risk should the brief note?
- A lab connects with wpasupplicant using PEAP settings after obtaining authorized credentials. What validation class does a successful join represent?
- A city asks whether adopting WPA3-Enterprise changes everything about PEAP risks overnight. What balanced answer should advisors give?
- An auditor wants proof that municipal staff cannot join a rogue AP broadcasting the corporate SSID. What assurance approach fits?
- A help desk resets Enterprise Wi-Fi passwords verbally in an open county office. What operational weakness near Enterprise controls does that illustrate?
- A RADIUS shared secret between a municipal wireless controller and the AAA server is trivial to guess. What infrastructure hardening issue should be raised?
- A municipal laptop Wi-Fi profile uses incorrect outer identity privacy settings during EAP. What identity-privacy awareness should IT apply?
- An assessor sees TLS alerts during EAP on a city Enterprise SSID. How should those clues be interpreted under rules of engagement?
- A city WLAN team wonders whether Fast BSS Transition (802.11r) can run with WPA2-Enterprise on staff SSIDs, or whether Enterprise forces them to drop roaming helpers. What awareness-level judgment should the assessor give?
- A municipal wireless report recommends replacing PEAP-MSCHAPv2 on the county staff SSID with EAP-TLS and enforcing certificate validation. What makes that remediation high quality for Enterprise Wi-Fi risk?
- A student on a city internship proposes capturing Enterprise Wi-Fi traffic and “just running aircrack like PSK.” What category error should the mentor correct?
- A city guest portal rides open/captive access while staff use WPA2-Enterprise on the same AP hardware. What multi-SSID security judgment matters most for assessment and design advice?
- During an authorized OffSec-style timed wireless scenario, recon shows AUTH/MGT rather than PSK on the target SSID. Which selection judgment should guide the candidate?