0006
Multiple organizations operating in the same vertical want to provide seamless wireless access for their employees
as they visit the other organizations.
Which of the following should be implemented if all the organizations use the native 802.1X client on their mobile devices?
Answer
Shibboleth
RADIUS Federation
SAML
OpenlD Connect
OAuth
Card 2
Question
0025
A company is currently using the following configuration:
- IAS server with certificate-based EAP-PEAP and MSCHAP
- Unencrypted authentication via PAP
A security administrator needs to configure a new wireless setup with the following configurations:
- PAP authentication method
- PEAP and EAP provide two-factor authentication
Which of the following forms of authentication are being used? (Select two.)
Answer
PAP
PEAP
MSCHAP
PEAP-MSCHAP
EAP
(EAP-)PEAP
Card 3
Question
0048
A user suspects someone has been accessing a home network without permission by spoofing the MAC address of
an authorized system. While attempting to determine if an authorized user is logged into the home network, the
user reviews the wireless router, which shows the following table for systems that are currently on the home
network.
Host IP Mac Mac Filter
DadPC 192.168.1.10 00:1d:blabla On
MomPC 192.168.1.10 21:13:blabla Off
JuniorPC 192.168.1.10 42:a7:blabla On
Unknown 192.168.1.10 10:b3:blabla Off
Which of the following should be the NEXT step to determine if there is an unauthorized user on the network?
Answer
Apply MAC filtering and see if the router drops any of the systems.
Physically check each of the authorized systems to determine if they are logged onto the network.
Deny the “unknown” host because the hostname is not known and MAC filtering is not applied to this host.
Conduct a ping sweep of each of the authorized systems and see if an echo response is received.
Card 4
Question
0054
A network administrator at a small office wants to simplify the configuration of mobile clients connecting to an
encrypted wireless network.
Which of the following should be implemented in the administrator does not want to provide the wireless password or the certificate to the employees?
Answer
WPS
802.1X
WPA2-PSK
TKIP
Card 5
Question
When connected to a secure WAP, which of the following encryption technologies is MOST likely to be configured
when connecting to WPA2-PSK?
Answer
DES
AES
MD5
WEP
Card 6
Question
0067
An administrator is replacing a wireless router. The configuration of the old wireless router was not documented
before it stopped functioning. The equipment connecting to the wireless network uses older legacy equipment
that was manufactured prior to the release of the 802.11i standard. Which of the following configuration options
should the administrator select for the new wireless router?
Answer
WPA+CCMP
WPA2+CCMP
WPA+TKIP
WPA2+TKIP
Card 7
Question
0079
An analyst wants to implement a more secure wireless authentication for office access points.
Which of the following technologies allows for encrypted authentication of wireless clients over TLS?
Answer
PEAP
WPA2
EAP
RADIUS
Card 8
Question
0083
A system administrator wants to provide balance between the security of a wireless network and usability. The
administrator is concerned with wireless encryption compatibility of older devices used by some employees.
Which of the following would provide strong security and backward compatibility when accessing the wireless
network?
Answer
WPA using a pre-shared key
Open wireless network and SSL VPN
WPA2 using a RADIUS back-end for 802.1X authentication
WEP with a 40-bit key
Card 9
Question
0086
A system administrator wants to provide for and enforce wireless access accountability during events where
external speakers are invited to make presentations to a mixed audience of employees and non-employees.
Which Shared accountsof the following should the administrator implement?
Answer
Shared accounts
Pre-shared passwords
Sponsored guest
Least privilege
Card 10
Question
0128
A security engineer is configuring a wireless network that must support mutual authentication of the wireless
client and the authentication server before users provide credentials. The wireless network must also support
authentication with usernames and passwords. Which of the following authentication protocols MUST the security
engineer select?
Answer
EAP-TLS
EAP-FAST
PEAP
EAP
Card 11
Question
0151
A network technician is setting up a segmented network that will utilize a separate ISP to provide wireless access to the public area for a company.
Which of the following wireless security methods should the technician implement to provide basic accountability for access to the public network?
Answer
Pre-shared key
Enterprise
Wi-Fi Protected Setup
Captive portal
Card 12
Question
0175
A technician is configuring a wireless guest network. After applying the most recent changes the technician finds
the new devices can no longer find the wireless network by name, but existing devices are still able to use the
wireless network.
Which of the following security measures did the technician MOST likely implement to cause this Scenario?
Answer
Deactivation of SSID broadcast
Activation of 802.1X with RADIUS
Reduction of WAP signal output power
Beacon interval was decreased
Implementation of MAC filtering
Card 13
Question
0195
A user of the wireless network is unable to gain access to the network. The symptoms are:
- Unable to connect to both internal and Internet resources
- The wireless icon shows connectivity but has no network access
The wireless network is WPA2 Enterprise and users must be a member of the wireless security group to authenticate.
Which of the following is the MOST likely cause of the connectivity issues?
Answer
The wireless signal is not strong enough
A remote DDoS attack against the RADIUS server is taking place
The user's laptop only supports WPA and WEP
The DHCP scope is full
The dynamic encryption key did not update while the user was offline
Card 14
Question
0214
Which of the following attack types is being carried out where a target is being sent unsolicited messages via
Bluetooth?
Answer
War chalking
Bluejacking
Bluesnarfing
Rogue tethering
Card 15
Question
0224
A security guard has informed the Chief Information Security Officer that a person with a tablet has been walking
around the building. The guard also noticed strange white markings in different areas of the parking lot.
The person is attempting which of the following types of attacks?
Answer
Jamming
Warchalking
Packet sniffing
Near field communication
Card 16
Question
0265
The SSID broadcast for a wireless router has been disabled but a network administrator notices that unauthorized
users are accessing the wireless network. The administer has determined that attackers are still able to detect the
presence of the wireless network despite the fact the SSID has been disabled.
Upgrade the encryption to WPA or WPA2Which of the following would further obscure the presence of the wireless network?
Answer
Upgrade the encryption to WPA or WPA2
Reroute wireless users to a honeypot
Create a non-zero length SSID for the wireless router
Disable responses to a broadcast probe request
Card 17
Question
0280
After correctly configuring a new wireless enabled thermostat to control the temperature of the company's
meeting room, Joe, a network administrator, determines that the thermostat is not connecting to the internet-
based control system. Joe verifies that the thermostat received the expected network parameters and it is
associated with the AP. Additionally, the other wireless mobile devices connected to the same wireless network
are functioning properly. The network administrator verified that the thermostat works when tested at his
residence.
Which of the following is the MOST likely reason the thermostat is not connecting to the internet?
Answer
The company implements a captive portal
The thermostat is using the incorrect encryption algorithm
The WPA2 shared key likely is incorrect
The company's DHCP server scope is full
Card 18
Question
0317
An attack that is using interference as its main attack to impede network traffic is which of the following?
Answer
Utilizing a previously unknown security flaw against the target
Introducing too much data to a target’s memory allocation
Using a similar wireless configuration of a nearby network
Inundating a target system with SYN requests
Card 19
Question
0325
The security administrator has noticed cars parking just outside of the building fence line.
Which of the following security measures can the administrator use to help protect the company's WiFi network against war driving? (Select TWO)
Answer
Create a honeynet
Reduce beacon rate
Add false SSIDs
Change antenna placement
Implement a warning banner
Adjust power level controls
Card 20
Question
0363
A security administrator wants to configure a company's wireless network in a way that will prevent wireless clients from broadcasting the company's SSID.
Which of the following should be configured on the company's
access points?
Answer
Enable ESSID broadcast
Enable protected management frames
Disable MAC authentication
Enable wireless encryption
Disable WPS
Disable SSID broadcast
How to use this set
Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.