WPS, Rogue AP & Captive Portal Attack Classes
OSWP · 55 questions
- A city AP still has WPS enabled 'for easy onboarding' on a staff SSID. Why do authorized assessors typically flag that setting?
- A municipal technician asks what WPS was originally intended to solve for consumers. What is the best description?
- In an authorized WPS assessment, an assessor contrasts online PIN attempt classes with offline pixie-class testing. What is the essential distinction?
- A wash-class survey of municipal APs marks several WPS-capable devices as locked. How should an assessor interpret that status for online PIN attack feasibility?
- A county asks for the simplest remediation when WPS is enabled on APs but is not required for onboarding. What should be recommended?
- A student argues that WPS risks only matter on legacy WEP networks. What correction should an instructor give?
- Study notes mention a reaver-class tool during WPS modules. Without providing a command recipe, what purpose class should a candidate remember?
- Inventory shows a city IoT SSID with WPS push-button configuration (PBC) enabled. What awareness point should the assessment highlight?
- An assessor documents vendor-specific WPS implementation bugs as a finding class on mixed municipal hardware. What reporting principle applies?
- A library floor walk finds a printer softAP advertising WPS while corporate controllers look clean. Why does that matter for Domain 6 inventory?
- A municipal IT lead proposes a rogue AP during an authorized wireless assessment to see whether staff join lookalike SSIDs. What goal best defines that evil-twin class of testing?
- A municipal blue team asks how client devices typically choose among duplicate SSIDs when a rogue AP appears nearby. Which theme best explains that preference behavior?
- During a city wireless lab, an assessor mentions hostapd as a building block for a controlled rogue AP. What purpose does hostapd serve in that context?
- hostapd-mana appears in Enterprise and rogue-AP coursework for a municipal purple-team lab. What mana-class purpose should the assessor state—without diving into configs?
- A county training session discusses Karma-style responses to client probe requests. At awareness depth, what does that Karma-class behavior do?
- A city SOC detects an unauthorized AP in a lobby. For OSWP-style literacy, how should detection work be framed relative to offensive rogue-AP study?
- An assessor clones a municipal guest open SSID for a controlled captive-portal test under RoE. How should that scenario be classified?
- A civic Wi-Fi captive portal asks users for an email address before granting Internet. What function does that portal primarily provide?
- A student claims HTTPS captive portals cannot be spoofed on a rogue network the assessor fully controls. What nuance about trust on that path is most accurate?
- DNS redirection concepts appear in a city's captive-portal lab. Why does DNS matter for portal behavior—without needing firewall recipes?
- A municipal assessment's rules of engagement forbid credential-harvesting portals. What should the assessor do regarding those techniques on that engagement?
- An evil twin in an authorized conference-room test advertises a stronger signal than the real municipal AP. What placement awareness should the assessor take away?
- A city asks whether client MAC randomization stops all evil-twin risks. What is the most accurate limit of that control?
- On an authorized rogue open AP, a fake captive portal prompts staff for a 'Wi-Fi password' field. How should that hybrid technique class be described?
- A municipal blue team maintains known-SSID and BSSID inventories to spot rogues. What defensive value does that inventory provide relative to offense literacy?
- An assessor must choose between WPS testing and rogue-AP testing against a locked-down municipal WPA3-SAE network with WPS disabled. Which selection principle applies?
- A stadium warns event staff about lookalike SSIDs during large events. As remediation when technical controls are incomplete, what does that user-awareness step primarily reduce?
- A city wireless lab documents both the fake portal page and recovered passphrase artifacts as evidence. Why keep those artifacts for the report?
- A city guest network already runs a legitimate captive portal. What testing-impact caution should guide an assessor's portal-related work?
- An intern wants to use wifiphisher-class automation on an OSWP-style exam-culture question for the city's practice drills. What policy stance should leadership reinforce?
- A municipal AP shows WPS enabled only on the 2.4 GHz radio while 5 GHz appears disabled for WPS. What configuration mistake does that partial state illustrate?
- A rogue AP offers open authentication while the real municipal network is WPA2. Why might some clients still join the weaker lookalike?
- A county asks whether Protected Management Frames (PMF) alone stop all evil-twin risks. What limitation is most accurate?
- An assessor reviewing wireless scans sees WPS states such as 'configured' versus 'not configured.' What should those flags guide?
- During an authorized purple-team exercise, a city hall lobby hosts a purpose-built free Wi-Fi pineapple-class rogue kit. What client-attraction framing should assessors emphasize?
- A civic assessment RoE allows a captive-portal awareness test that visually clones the municipal guest login theme. What ethics constraint still applies?
- During an authorized municipal WPS PIN test, SIEM alerts fire from AP logs that show repeated WPS authentication failures. What assessment insight does that highlight?
- A city AP aggressively lockouts online WPS PIN attempts. At concept level, how should an authorized assessor adapt?
- A library kiosk is configured to auto-join the strongest SSID named LibraryGuest. Why does that increase evil-twin risk?
- A city asks for architectural remediation against rogue APs that goes beyond user awareness training. Which theme set best fits?
- In a municipal captive-portal lab on a rogue AP host, why is an HTTP (web) service typically required?
- Why do authorized rogue-AP labs typically include DHCP service for victim clients?
- An assessor must choose between attempting WPA2-PSK credential recovery and deploying a captive-portal rogue against a conference guest SSID. What should drive the choice?
- A municipal policy bans personal hotspots that reuse or closely collide with corporate SSID names. What risk is that policy trying to reduce?
- A municipal wireless report marks a WPS finding critical because successful WPS abuse reveals the network PSK. What severity framing is that using?
- A city wants to keep push-button WPS available only when an admin is physically present. How should an OSWP-style assessment view that control?
- An authorized evil twin targets clients that expect a PSK network. What handshake-related outcome can that rogue class induce?
- A captive-portal lab records browser and OS captive-detection endpoint probes. Why do assessors care about those probes?
- A nonprofit asks whether an open guest SSID plus captive portal is secure enough for staff workflows that handle PII. What is the sound OSWP-aligned answer?
- After an authorized municipal rogue-AP test window ends, what engagement hygiene is required?
- A wash-class scan shows WPS version and manufacturer metadata on a city AP. What is the correct interpretation before claiming a finding?
- A city council demo accidentally leaves a lab rogue SSID running overnight in the building. What lesson should the after-action note emphasize?
- A municipal wireless assessment report recommends WIPS signatures tuned for evil-twin detection. Why include that defensive advice?
- A student proposes RF jamming to force municipal clients onto a lab rogue AP. What is the correct OSWP-aligned response?
- A municipal AP presents WPS enabled, a weak open guest portal, and a strong WPA3-SAE staff SSID. Within RoE, which surface should the assessor prioritize first?