
2023 PrepAwayETE CWNP CWSP-206 Dumps and Exam Test Engine
CWNP CWSP-206 DUMPS WITH REAL EXAM QUESTIONS
NEW QUESTION # 81
Which of the following encryption methods uses AES technology?
- A. Static WEP
- B. CCMP
- C. TKIP
- D. Dynamic WEP
Answer: B
NEW QUESTION # 82
XYZ Hospital plans to improve the security and performance of their Voice over Wi-Fi implementation and will be upgrading to 802.11n phones with 802.1X/EAP authentication. XYZ would like to support fast secure roaming for the phones and will require the ability to troubleshoot reassociations that are delayed or dropped during inter-channel roaming. What portable solution would be recommended for XYZ to troubleshoot roaming problems?
- A. Spectrum analyzer software installed on a laptop computer.
- B. Laptop-based protocol analyzer with multiple 802.11n adapters.
- C. WIPS sensor software installed on a laptop computer.
- D. An autonomous AP mounted on a mobile cart and configured to operate in monitor mode.
Answer: B
NEW QUESTION # 83
In the basic 4-way handshake used in secure 802.11 networks, what is the purpose of the ANonce and SNonce?
- A. They are added together and used as the GMK, fromwhich the GTK is derived.
- B. They are used to pad Message 1 and Message 2 so each frame contains the same number of bytes.
- C. They are input values used in the derivation of the Pairwise Transient Key.
- D. The IEEE 802.11 standard requires that all encrypted frames contain a nonce to serve as a Message Integrity Check (MIC).
Answer: C
NEW QUESTION # 84
Which of the following DoS attacks affects mostly Windows computers by sending corrupt UDP packets?
- A. Smurf
- B. Ping flood
- C. Fraggle
- D. Bonk
Answer: D
NEW QUESTION # 85
ABC Corporation is evaluating the security solution for their existing WLAN. Two of their supported solutions include a PPTP VPN and 802.1X/LEAP. They have used PPTP VPNs because of their wide support in server and desktop operating systems. While both PPTP and LEAP adhere to the minimum requirements of the corporate security policy, some individuals have raised concerns about MS-CHAPv2 (and similar) authentication and the known fact that MS-CHAPv2 has proven vulnerable in improper implementations. As a consultant, what do you tell ABC Corporation about implementing MS-CHAPv2 authentication?
- A. LEAP's use of MS-CHAPv2 is only secure when combined with WEP.
- B. MS-CHAPv2 uses AES authentication, and is therefore secure.
- C. When implemented with AES-CCMP encryption, MS-CHAPv2 is very secure.
- D. MS-CHAPv2 is compliant with WPA-Personal, but not WPA2-Enterprise.
- E. MS-CHAPv2 is only appropriate for WLAN security when used inside a TLS-encrypted tunnel.
Answer: E
Explanation:
Explanation/Reference:
NEW QUESTION # 86
As the primary security engineer for a large corporate network, you have been asked to author a new securitypolicy for the wireless network. While most client devices support 802.1X authentication, some legacy devices still only support passphrase/PSK-based security methods. When writing the 802.11 security policy, what password-related items should be addressed?
- A. Password complexity should be maximized so that weak WEP IV attacks are prevented.
- B. MS-CHAPv2 passwords used with EAP/PEAPv0 should be stronger than typical WPA2-PSK passphrases.
- C. Certificates should always be recommended instead of passwords for 802.11 client authentication.
- D. Static passwords should be changed on a regular basis to minimize the vulnerabilities of a PSK-based authentication.
- E. EAP-TLS must be implemented in such scenarios.
Answer: D
NEW QUESTION # 87
Joe's new laptop is experiencing difficulty connecting to ABC Company's 802.11 WLAN using 802.1X/EAP PEAPv0. The company's wireless networkadministrator assured Joe that his laptop was authorized in the WIPS management console for connectivity to ABC's network before it was given to him. The WIPS termination policy includes alarms for rogue stations, rogue APs, DoS attacks and unauthorized roaming.
What is a likely reason that Joe cannot connect to the network?
- A. An ASLEAP attack has been detected on APs to which Joe's laptop was trying to associate. The WIPS responded by disabling the APs.
- B. Joe's integrated 802.11 radio is sending multiple Probe Request frames on each channel.
- C. Joe configured his 802.11 radio card to transmit at 100 mW to increase his SNR. The WIPS is detecting this much output power as a DoS attack.
- D. Joe disabled his laptop's integrated 802.11 radio and is using a personal PC card radio with a different chipset, drivers, and client utilities.
Answer: D
NEW QUESTION # 88
Which of the following protocols is used to compare two values calculated using the Message Digest (MD5) hashing function?
- A. EAP-TLS
- B. CHAP
- C. EAP
- D. PEAP
Answer: B
NEW QUESTION # 89
The Marketing department's WLAN users need to reach their file and email server as well as the Internet, but should not have access to any other network resources. What single WLAN security feature should be implemented to comply with these requirements?
- A. Role-based access control
- B. Captive portal
- C. Group authentication
- D. RADIUS policy accounting
- E. Mutual authentication
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION # 90
In a security penetration exercise, a WLAN consultant obtains the WEP key of XYZ Corporation's wireless network. Demonstrating the vulnerabilities of using WEP, the consultant uses a laptop running asoftware AP in an attempt to hijack the authorized user's connections. XYZ's legacy network is using 802.11n APs with
802.11b, 11g, and 11n client devices. With this setup, how can the consultant cause all of the authorized clients to establish Layer 2 connectivity with the software access point?
- A. A higher SSID priority value configured in the Beacon frames of the consultant's software AP will take priority over the SSID in the authorized AP, causing the clients to reassociate.
- B. All WLAN clients will reassociate to the consultant's software AP if the consultant's software AP provides the same SSID on any channel with a 10 dB SNR improvement over the authorized AP.
- C. When the RF signal between the clients and the authorized AP is temporarily disrupted and the consultant's software AP is using the same SSID on a different channel than the authorized AP, the clients will reassociate to the software AP.
- D. If the consultant's software AP broadcasts Beacon frames that advertise 802.11g data rates that are faster rates than XYZ's current 802.11b data rates, all WLAN clients will reassociate to the faster AP.
Answer: C
NEW QUESTION # 91
Your Company is receiving false and abusive e-mails from the e-mail address of your partner company. When you complain, the partner company tells you that they have never sent any such e-mails. Which of the following types of cyber crimes involves this form of network attack?
- A. Spoofing
- B. Cyber Stalking
- C. Cyber squatting
- D. Man-in-the-middle attack
Answer: A
NEW QUESTION # 92
The IEEE 802.11 Pairwise Transient Key (PTK) is derived from what cryptographic element?
- A. Group Temporal Key (GTK)
- B. Pairwise Master Key (PMK)
- C. Phase Shift Key (PSK)
- D. PeerKey (PK)
- E. Group Master Key (GMK)
- F. Key Confirmation Key (KCK)
Answer: B
NEW QUESTION # 93
You have a Windows laptop computer with an integrated, dual-band, Wi-Fi compliant adapter. Your laptop computer has protocol analyzer softwareinstalled that is capable of capturing and decoding 802.11ac data.
What statement best describes the likely ability to capture 802.11ac frames for security testing purposes?
- A. Laptops cannot be used to capture 802.11ac frames because they do not support MU-MIMO.
- B. The only method available to capture 802.11ac frames is to perform a remote capture with a compatible access point.
- C. Only Wireshark can be used tocapture 802.11ac frames as no other protocol analyzer has implemented the proper frame decodes.
- D. All integrated 802.11ac adapters will work with most protocol analyzers for frame capture, including the Radio Tap Header.
- E. Integrated 802.11ac adapters are not typically compatible with protocol analyzers in Windows laptops. It is often best to use a USB adapter or carefully select a laptop with an integrated adapter that will work.
Answer: E
NEW QUESTION # 94
Which of the following is a networking protocol that provides centralized authentication, authorization, and accounting (AAA) management for computers to connect and use a network service?
- A. HTTP
- B. RADIUS
- C. SSL
- D. IPSec
Answer: B
NEW QUESTION # 95
ABC Company is deploying an IEEE 802.11-compliant wireless security solution using
802.1X/EAP authentication. According to company policy, the security solution must prevent an eavesdropper from decrypting data frames traversing a wireless connection. What security characteristic and/or component plays a role in preventing data decryption?
- A. Integrity Check Value (ICV)
- B. PLCP Cyclic Redundancy Check (CRC)
- C. Encrypted Passphrase Protocol (EPP)
- D. 4-Way Handshake
- E. Multi-factor authentication
Answer: D
NEW QUESTION # 96
Which of the following is the most secure protocol used for encryption in a wireless network?
- A. WEP
- B. IPSec
- C. WPA2
- D. WPA
Answer: C
NEW QUESTION # 97
You are installing 6 APs on the outside of your facility. They will be mounted at a height of 6 feet.
What must you do to implement these APs in a secure manner beyond the normal indoor AP implementations? (Choose the single best answer.)
- A. Use external antennas.
- B. Use internal antennas.
- C. Power the APs using PoE.
- D. Ensure proper physical and environmental security using outdoor ruggedized APs or enclosures.
Answer: D
NEW QUESTION # 98
The following numbered items show some of the contents of each of the four frames exchanged during the
4-way handshake.
* Encrypted GTK sent
* Confirmation of temporal key installation
* ANonce sent from authenticator to supplicant
* SNonce sent from supplicant to authenticator, MIC included
Arrange the frames in the correct sequence beginning with the start of the 4-way handshake.
- A. 2, 3, 4, 1
- B. 4, 3, 1, 2
- C. 3, 4, 1, 2
- D. 1, 2, 3, 4
Answer: C
NEW QUESTION # 99
Which of the following provides the best protection against a man-in-the-middle attack?
- A. Strong encryption
- B. Firewall
- C. Strong password
- D. Fiber-optic cable
Answer: A
NEW QUESTION # 100
The Marketing department's WLAN users need to reach their file and email server as well as the Internet, but should not have access to any other network resources. What single WLAN security feature should beimplemented to comply with these requirements?
- A. Role-based access control
- B. Captive portal
- C. Group authentication
- D. RADIUS policy accounting
- E. Mutual authentication
Answer: A
NEW QUESTION # 101
Which of the following protocols is designed to provide more secure encryption than the weak wired encryption privacy?
- A. CCMP
- B. LEAP
- C. TKIP
- D. PEAP
Answer: C
NEW QUESTION # 102
Fred works primarily from home and public wireless hotspots rather than commuting to office. He frequently accesses the office network remotely from his Mac laptop using the local 802.11 WLAN. In this remote scenario, what single wirelesssecurity practice will provide the greatest security for Fred?
- A. Use enterprise WIPS on the corporate office network.
- B. Use only HTTPS when agreeing to acceptable use terms on public networks.
- C. Use 802.1X/PEAPv0 to connect to the corporate office network from public hotspots.
- D. Use an IPSec VPN for connectivity to the office network.
- E. Use secure protocols, such as FTP, for remote file transfers.
- F. Use WIPS sensor software on the laptop to monitor for risks and attacks.
Answer: D
NEW QUESTION # 103
Which of the following is a security access control technique that allows or prevents specific network devices from accessing the network?
- A. Route filtering
- B. MAC filtering
- C. Packet filtering
- D. Ingress filtering
Answer: B
NEW QUESTION # 104
......
2023 New PrepAwayETE CWSP-206 PDF Recently Updated Questions: https://www.prepawayete.com/CWNP/CWSP-206-practice-exam-dumps.html
CWSP-206 Exam with Guarantee Updated 138 Questions: https://drive.google.com/open?id=1iEYjJMfjaNFVVn1qk6JT8Vrjc8rnMjLq