An authorized evil-twin lab against a municipal PEAP deployment captures MSCHAPv2 challenge/response material. How should that material be classified?
Select an answer to reveal the explanation.
Short Explanation
MSCHAPv2 challenge/response from an authorized twin lab is offline-crackable credential material when weak passwords sit behind PEAP—not SAE commits, WEP IV dumps, or forest names in beacons.
Full Explanation
When weak password-based inner methods such as MSCHAPv2 are exposed to a rogue Enterprise path, assessors may obtain challenge/response material suitable for offline recovery classes in authorized testing. That classification differs from WPA3-SAE Personal handshake artifacts, WEP IV statistical attacks, or beacon-derived directory metadata. Document the class and keep methods within RoE; do not publish exploit recipes.