
CWSP-207問題集には練習試験問題解答
CWSP-207はCWNP CWSP実際の無料試験練習テスト
質問 # 20
When used as part of a WLAN authentication solution, what is the role of LDAP?
- A. An Authentication Server (AS) that communicates directly with, and provides authentication for, the Supplicant.
- B. A SQL compliant authentication service capable of dynamic key generation and distribution
- C. An IEEE X.500 standard compliant database that participates in the 802.1X port-based access control process
- D. A data retrieval protocol used by an authentication service such as RADIUS
- E. A role-based access control protocol for filtering data to/from authenticated stations.
正解:D
質問 # 21
What statement accurately describes the functionality of the IEEE 802.1X standard?
- A. Port-based access control, which allows three frame types to traverse the uncontrolled port: EAP, DHCP, and DNS.
- B. Port-based access control with dynamic encryption key management and distribution
- C. Port-based access control with EAP encapsulation over the LAN (EAPoL)
- D. Port-based access control with support for authenticated-user VLANs only
- E. Port-based access control with mandatory support of AES-CCMP encryption
正解:C
質問 # 22
When using the 802.1X/EAP framework for authentication in 802.11 WLANs, why is the 802.1X Controlled Port still blocked after the 802.1X/EAP framework has completed successfully?
- A. The 802.1X Controlled Port is always blocked, but the Uncontrolled Port opens after the EAP authentication process completes.
- B. The 802.1X Controlled Port is blocked until Vender Specific Attributes (VSAs) are exchanged inside a RADIUS packet between the Authenticator and Authentication Server.
- C. The 4-Way Handshake must be performed before the 802.1X Controlled Port changes to the unblocked state.
- D. The 802.1X Controlled Port remains blocked until an IP address is requested and accepted by the Supplicant.
正解:C
質問 # 23
Given: In a security penetration exercise, a WLAN consultant obtains the WEP key of XYZ Corporation's wireless network. Demonstrating the vulnerabilities of using WEP, the consultant uses a laptop running a software AP in an attempt to hijack the authorized user's connections. XYZ's legacy network is using 802.11n APs with 802.11b, 11g, and 11n client devices.
With this setup, how can the consultant cause all of the authorized clients to establish Layer 2 connectivity with the software access point?
- A. A higher SSID priority value configured in the Beacon frames of the consultant's software AP will take priority over the SSID in the authorized AP, causing the clients to reassociate.
- B. All WLAN clients will reassociate to the consultant's software AP if the consultant's software AP provides the same SSID on any channel with a 10 dB SNR improvement over the authorized AP.
- C. If the consultant's software AP broadcasts Beacon frames that advertise 802.11g data rates that are faster rates than XYZ's current 802.11b data rates, all WLAN clients will reassociate to the faster AP.
- D. When the RF signal between the clients and the authorized AP is temporarily disrupted and the consultant's software AP is using the same SSID on a different channel than the authorized AP, the clients will reassociate to the software AP.
正解:D
質問 # 24
What is a primary criteria for a network to qualify as a Robust Security Network (RSN)?
- A. WLAN controllers and APs must not support SSHv1.
- B. WEP may not be used for encryption.
- C. Token cards must be used for authentication.
- D. WPA-Personal must be supported for authentication and encryption.
- E. Dynamic WEP-104 encryption must be enabled.
正解:B
質問 # 25
As a part of a large organization's security policy, how should a wireless security professional address the problem of rogue access points?
- A. A trained employee should install and configure a WIPS for rogue detection and response measures.
- B. Use a WPA2-Enterprise compliant security solution with strong mutual authentication and encryption for network access of corporate devices.
- C. Hide the SSID of all legitimate APs on the network so that intruders cannot copy this parameter on rogue APs.
- D. Enable port security on Ethernet switch ports with a maximum of only 3 MAC addresses on each port.
- E. Conduct thorough manual facility scans with spectrum analyzers to detect rogue AP RF signatures.
正解:A
質問 # 26
You are using a protocol analyzer for random checks of activity on the WLAN. In the process, you notice two different EAP authentication processes. One process (STA1) used seven EAP frames (excluding ACK frames) before the 4-way handshake and the other (STA2) used 11 EAP frames (excluding ACK frames) before the
4-way handshake.
Which statement explains why the frame exchange from one STA required more frames than the frame exchange from another STA when both authentications were successful? (Choose the single most probable answer given a stable WLAN.)
- A. STA1 and STA2 are using different EAP types.
- B. STA1 and STA2 are using different cipher suites.
- C. STA1 is a reassociation and STA2 is an initial association.
- D. STA2 has retransmissions of EAP frames.
- E. STA1 is a TSN, and STA2 is an RSN.
正解:A
質問 # 27
Given: An 802.1X/EAP implementation includes an Active Directory domain controller running Windows Server 2012 and an AP from a major vendor. A Linux server is running RADIUS and it queries the domain controller for user credentials. A Windows client is accessing the network.
What device functions as the EAP Supplicant?
- A. Linux server
- B. Windows server
- C. An unlisted switch
- D. Windows client
- E. An unlisted WLAN controller
- F. Access point
正解:D
質問 # 28
When implementing a WPA2-Enterprise security solution, what protocol must the selected RADIUS server support?
- A. LWAPP, GRE, or CAPWAP
- B. EAP
- C. LDAP
- D. IPSec/ESP
- E. CCMP and TKIP
正解:B
質問 # 29
Given: XYZ Company has recently installed an 802.11ac WLAN. The company needs the ability to control access to network services, such as file shares, intranet web servers, and Internet access based on an employee's job responsibilities.
What WLAN security solution meets this requirement?
- A. A VPN server with multiple DHCP scopes
- B. WPA2-Personal with support for LDAP queries
- C. An autonomous AP system with MAC filters
- D. A WLAN controller with RBAC features
- E. A WLAN router with wireless VLAN support
正解:D
質問 # 30
ABC Company uses the wireless network for highly sensitive network traffic. For that reason, they intend to protect their network in all possible ways. They are continually researching new network threats and new preventative measures. They are interested in the security benefits of 802.11w, but would like to know its limitations.
What types of wireless attacks are protected by 802.11w? (Choose 2)
- A. Robust management frame replay attacks
- B. RF DoS attacks
- C. Social engineering attacks
- D. Layer 2 Disassociation attacks
正解:A、D
質問 # 31
Given: You support a coffee shop and have recently installed a free 802.11ac wireless hot-spot for the benefit of your customers. You want to minimize legal risk in the event that the hot-spot is used for illegal Internet activity.
What option specifies the best approach to minimize legal risk at this public hot-spot while maintaining an open venue for customer Internet access?
- A. Configure WPA2-Enterprise security on the access point
- B. Allow only trusted patrons to use the WLAN
- C. Implement a captive portal with an acceptable use disclaimer
- D. Block TCP port 25 and 80 outbound on the Internet router
- E. Use a WIPS to monitor all traffic and deauthenticate malicious stations
- F. Require client STAs to have updated firewall and antivirus software
正解:C
質問 # 32
You are using a utility that takes input and generates random output. For example, you can provide the input of a known word as a secret word and then also provide another known word as salt input. When you process the input it generates a secret code which is a combination of letters and numbers with case sensitivity. For what is the described utility used? (Choose 3)
- A. Generating passwords for WLAN infrastructure equipment logins
- B. Generating PMKs that can be imported into 802.11 RSN-compatible devices
- C. Generating secret keys for RADIUS servers and WLAN infrastructure devices
- D. Generating passphrases for WLAN systems secured with WPA2-Personal
- E. Generating dynamic session keys used for IPSec VPNs
正解:A、C、D
質問 # 33
What 802.11 WLAN security problem is directly addressed by mutual authentication?
- A. Wireless hijacking attacks
- B. MAC spoofing
- C. Weak Initialization Vectors
- D. Weak password policies
- E. Disassociation attacks
- F. Offline dictionary attacks
正解:A
質問 # 34
In what deployment scenarios would it be desirable to enable peer-to-peer traffic blocking?
- A. In corporate Voice over Wi-Fi networks with push-to-talk multicast capabilities
- B. At public hot-spots in which many clients use diverse applications
- C. In home networks in which file and printer sharing is enabled
- D. In university environments using multicast video training sourced from professor's laptops
正解:B
質問 # 35
Given: ABC Company has a WLAN controller using WPA2-Enterprise with PEAPv0/MS-CHAPv2 and AES-CCMP to secure their corporate wireless data. They wish to implement a guest WLAN for guest users to have Internet access, but want to implement some security controls. The security requirements for the hot-spot include:
* Cannot access corporate network resources
* Network permissions are limited to Internet access
* All stations must be authenticated
What security controls would you suggest? (Choose the single best answer.)
- A. Force all guest users to use a common VPN protocol to connect.
- B. Configure access control lists (ACLs) on the guest WLAN to control data types and destinations.
- C. Require guest users to authenticate via a captive portal HTTPS login page and place the guest WLAN and the corporate WLAN on different VLANs.
- D. Implement separate controllers for the corporate and guest WLANs.
- E. Use a WIPS to deauthenticate guest users when their station tries to associate with the corporate WLAN.
正解:C
質問 # 36
Given: WLAN attacks are typically conducted by hackers to exploit a specific vulnerability within a network.
What statement correctly pairs the type of WLAN attack with the exploited vulnerability? (Choose 3)
- A. Zero-day attacks are always authentication or encryption cracking attacks.
- B. Social engineering attacks are performed to collect sensitive information from unsuspecting users
- C. Association flood attacks are Layer 3 DoS attacks performed against authenticated client stations
- D. RF DoS attacks prevent successful wireless communication on a specific frequency or frequency range.
- E. Hijacking attacks interrupt a user's legitimate connection and introduce a new connection with an evil twin AP.
- F. Management interface exploit attacks are attacks that use social engineering to gain credentials from managers.
正解:B、D、E
質問 # 37
Joe's new laptop is experiencing difficulty connecting to ABC Company's 802.11 WLAN using 802.1X/EAP PEAPv0. The company's wireless network administrator assured Joe that his laptop was authorized in the WIPS management console for connectivity to ABC's network before it was given to him. The WIPS termination policy includes alarms for rogue stations, roque APs, DoS attacks and unauthorized roaming.
What is a likely reason that Joe cannot connect to the network?
- A. Joe disabled his laptop's integrated 802.11 radio and is using a personal PC card radio with a different chipset, drivers, and client utilities.
- B. Joe's integrated 802.11 radio is sending multiple Probe Request frames on each channel.
- C. An ASLEAP attack has been detected on APs to which Joe's laptop was trying to associate. The WIPS responded by disabling the APs.
- D. Joe configured his 802.11 radio card to transmit at 100 mW to increase his SNR. The WIPS is detecting this much output power as a DoS attack.
正解:A
質問 # 38
What statement is true regarding the nonces (ANonce and SNonce) used in the IEEE 802.11 4 Way Handshake?
- A. The nonces are created by combining the MAC addresses of the Supplicant, Authenticator, and Authentication Server into a mixing algorithm.
- B. The Supplicant uses the SNonce to derive its unique PTK and the Authenticator uses the ANonce to derive its unique PTK, but the nonces are not shared.
- C. Nonces are sent in EAPoL frames to indicate to the receiver that the sending station has installed and validated the encryption keys.
- D. Both nonces are used by the Supplicant and Authenticator in the derivation of a single PTK.
正解:D
質問 # 39
What software and hardware tools are used together to hijack a wireless station from the authorized wireless network onto an unauthorized wireless network? (Choose 2)
- A. DHCP server software and access point software
- B. MAC spoofing software and MAC DoS software
- C. A low-gain patch antenna and terminal emulation software
- D. RF jamming device and a wireless radio card
- E. A wireless workgroup bridge and a protocol analyzer
正解:A、D
質問 # 40
Given: Your network implements an 802.1X/EAP-based wireless security solution. A WLAN controller is installed and manages seven APs. FreeRADIUS is used for the RADIUS server and is installed on a dedicated server named SRV21. One example client is a MacBook Pro with 8 GB RAM.
What device functions as the 802.1X/EAP Authenticator?
- A. WLAN Controller/AP
- B. RADIUS server
- C. SRV21
- D. MacBook Pro
正解:A
質問 # 41
What is the purpose of the Pairwise Transient Key (PTK) in IEEE 802.11 Authentication and Key Management?
- A. The PTK is used to encrypt the Pairwise Master Key (PMK) for distribution to the 802.1X Authenticator prior to the 4-Way Handshake.
- B. The PTK is XOR'd with the PSK on the Authentication Server to create the AAA key.
- C. The PTK is a type of master key used as an input to the GMK, which is used for encrypting multicast data frames.
- D. The PTK contains keys that are used to encrypt unicast data frames that traverse the wireless medium.
正解:D
質問 # 42
......
無料CWNP CWSP CWSP-207試験問題:https://www.goshiken.com/CWNP/CWSP-207-mondaishu.html
CWSP-207問題集でCWNP CWSP必ず合格できる練習問題集:https://drive.google.com/open?id=1ESfnOZLpZC_H83bVBqx71oACUldGdES3