[Aug-2024] The Best CWNP CWSP CWSP-207 Professional Exam Questions [Q16-Q41]

Share

[Aug-2024] The Best CWNP CWSP CWSP-207 Professional Exam Questions

Try 100% Updated CWSP-207 Exam Questions [2024]

NEW QUESTION # 16
The IEEE 802.11 Pairwise Transient Key (PTK) is derived from what cryptographic element?

  • A. Key Confirmation Key (KCK)
  • B. Pairwise Master Key (PMK)
  • C. Phase Shift Key (PSK)
  • D. PeerKey (PK)
  • E. Group Master Key (GMK)
  • F. Group Temporal Key (GTK)

Answer: B


NEW QUESTION # 17
Given: Your network implements an 802.1X/EAP-based wireless security solution. A WLAN controller is installed and manages seven APs. FreeRADIUS is used for the RADIUS server and is installed on a dedicated server named SRV21. One example client is a MacBook Pro with 8 GB RAM.
What device functions as the 802.1X/EAP Authenticator?

  • A. RADIUS server
  • B. SRV21
  • C. WLAN Controller/AP
  • D. MacBook Pro

Answer: C


NEW QUESTION # 18
What WLAN client device behavior is exploited by an attacker during a hijacking attack?

  • A. Client drivers scan for and connect to access points in the 2.4 GHz band before scanning the 5 GHz band.
  • B. When the RF signal between a client and an access point is disrupted for more than a few seconds, the client device will attempt to associate to an access point with better signal quality.
  • C. When the RF signal between a client and an access point is lost, the client will not seek to reassociate with another access point until the 120 second hold down timer has expired.
  • D. After the initial association and 4-way handshake, client stations and access points do not need to perform another 4-way handshake, even if connectivity is lost.
  • E. As specified by the Wi-Fi Alliance, clients using Open System authentication must allow direct client-to-client connections, even in an infrastructure BSS.

Answer: B


NEW QUESTION # 19
Given: XYZ Company has recently installed an 802.11ac WLAN. The company needs the ability to control access to network services, such as file shares, intranet web servers, and Internet access based on an employee's job responsibilities.
What WLAN security solution meets this requirement?

  • A. A VPN server with multiple DHCP scopes
  • B. WPA2-Personal with support for LDAP queries
  • C. A WLAN router with wireless VLAN support
  • D. An autonomous AP system with MAC filters
  • E. A WLAN controller with RBAC features

Answer: E


NEW QUESTION # 20
What elements should be addressed by a WLAN security policy? (Choose 2)

  • A. Social engineering recognition and mitigation techniques
  • B. Enabling encryption to prevent MAC addresses from being sent in clear text
  • C. How to prevent non-IT employees from learning about and reading the user security policy
  • D. End-user training for password selection and acceptable network use
  • E. The exact passwords to be used for administration interfaces on infrastructure devices

Answer: A,D


NEW QUESTION # 21
Joe's new laptop is experiencing difficulty connecting to ABC Company's 802.11 WLAN using 802.1X/EAP PEAPv0. The company's wireless network administrator assured Joe that his laptop was authorized in the WIPS management console for connectivity to ABC's network before it was given to him. The WIPS termination policy includes alarms for rogue stations, roque APs, DoS attacks and unauthorized roaming.
What is a likely reason that Joe cannot connect to the network?

  • A. Joe disabled his laptop's integrated 802.11 radio and is using a personal PC card radio with a different chipset, drivers, and client utilities.
  • B. Joe's integrated 802.11 radio is sending multiple Probe Request frames on each channel.
  • C. An ASLEAP attack has been detected on APs to which Joe's laptop was trying to associate. The WIPS responded by disabling the APs.
  • D. Joe configured his 802.11 radio card to transmit at 100 mW to increase his SNR. The WIPS is detecting this much output power as a DoS attack.

Answer: A


NEW QUESTION # 22
Given: An 802.1X/EAP implementation includes an Active Directory domain controller running Windows Server 2012 and an AP from a major vendor. A Linux server is running RADIUS and it queries the domain controller for user credentials. A Windows client is accessing the network.
What device functions as the EAP Supplicant?

  • A. Windows server
  • B. Linux server
  • C. An unlisted WLAN controller
  • D. Windows client
  • E. An unlisted switch
  • F. Access point

Answer: D


NEW QUESTION # 23
Given: ABC Company has recently installed a WLAN controller and configured it to support WPA2-Enterprise security. The administrator has configured a security profile on the WLAN controller for each group within the company (Marketing, Sales, and Engineering).
How are authenticated users assigned to groups so that they receive the correct security profile within the WLAN controller?

  • A. The RADIUS server forwards the request for a group attribute to an LDAP database service, and LDAP sends the group attribute to the WLAN controller.
  • B. The RADIUS server sends the list of authenticated users and groups to the WLAN controller as part of a
    4-Way Handshake prior to user authentication.
  • C. The RADIUS server sends a group name return list attribute to the WLAN controller during every successful user authentication.
  • D. The WLAN controller polls the RADIUS server for a complete list of authenticated users and groups after each user authentication.

Answer: C


NEW QUESTION # 24
You are implementing an 802.11ac WLAN and a WIPS at the same time. You must choose between integrated and overlay WIPS solutions. Which of the following statements is true regarding integrated WIPS solutions?

  • A. Many integrated WIPS solutions that detect Voice over Wi-Fi traffic will cease scanning altogether to accommodate the latency sensitive client traffic.
  • B. Integrated WIPS is always more expensive than overlay WIPS.
  • C. Integrated WIPS use special sensors installed alongside the APs to scan for threats.
  • D. Integrated WIPS always perform better from a client throughput perspective because the same radio that performs the threat scanning also services the clients.

Answer: A


NEW QUESTION # 25
What preventative measures are performed by a WIPS against intrusions?

  • A. EAPoL Reject frame flood against a rogue AP
  • B. Deauthentication attack against a classified neighbor AP
  • C. Evil twin attack against a rogue AP
  • D. ASLEAP attack against a rogue AP
  • E. Uses SNMP to disable the switch port to which rogue APs connect

Answer: E


NEW QUESTION # 26
Given: The ABC Corporation currently utilizes an enterprise Public Key Infrastructure (PKI) to allow employees to securely access network resources with smart cards. The new wireless network will use WPA2-Enterprise as its primary authentication solution. You have been asked to recommend a Wi-Fi Alliance-tested EAP method.
What solutions will require the least change in how users are currently authenticated and still integrate with their existing PKI?

  • A. EAP-TTLS/MSCHAPv2
  • B. PEAPv0/EAP-TLS
  • C. EAP-TLS
  • D. PEAPv0/EAP-MSCHAPv2
  • E. EAP-FAST
  • F. LEAP

Answer: C


NEW QUESTION # 27
What is a primary criteria for a network to qualify as a Robust Security Network (RSN)?

  • A. Dynamic WEP-104 encryption must be enabled.
  • B. WPA-Personal must be supported for authentication and encryption.
  • C. Token cards must be used for authentication.
  • D. WEP may not be used for encryption.
  • E. WLAN controllers and APs must not support SSHv1.

Answer: D


NEW QUESTION # 28
In an effort to optimize WLAN performance, ABC Company has upgraded their WLAN infrastructure from
802.11a/g to 802.11n. 802.11a/g clients are still supported and are used throughout ABC's facility. ABC has always been highly security conscious, but due to budget limitations, they have not yet updated their overlay WIPS solution to 802.11n or 802.11ac.
Given ABC's deployment strategy, what security risks would not be detected by the 802.11a/g WIPS?

  • A. 802.11a STA performing a deauthentication attack against 802.11n APs
  • B. 802.11n client spoofing the MAC address of an authorized 802.11n client
  • C. Rogue AP operating in Greenfield 40 MHz-only mode
  • D. Hijacking attack performed by using a rogue 802.11n AP against an 802.11a client

Answer: C


NEW QUESTION # 29
What policy would help mitigate the impact of peer-to-peer attacks against wireless-enabled corporate laptop computers when the laptops are also used on public access networks such as wireless hot-spots?

  • A. Require WPA2-Enterprise as the minimal WLAN security solution.
  • B. Require secure applications such as POP, HTTP, and SSH.
  • C. Require VPN software for connectivity to the corporate network.
  • D. Require Port Address Translation (PAT) on each laptop.

Answer: C


NEW QUESTION # 30
Given: Your network includes a controller-based WLAN architecture with centralized data forwarding. The AP builds an encrypted tunnel to the WLAN controller. The WLAN controller is uplinked to the network via a trunked 1 Gbps Ethernet port supporting all necessary VLANs for management, control, and client traffic.
What processes can be used to force an authenticated WLAN client's data traffic into a specific VLAN as it exits the WLAN controller interface onto the wired uplink? (Choose 3)

  • A. Configure the WLAN controller with static SSID-to-VLAN mappings; the user will be assigned to a VLAN according to the SSID being used.
  • B. During 802.1X authentication, RADIUS sends a return list attribute to the WLAN controller assigning the user and all traffic to a specific VLAN.
  • C. On the Ethernet switch that connects to the AP, configure the switch port as an access port (not trunking) in the VLAN of supported clients.
  • D. In the WLAN controller's local user database, create a static username-to-VLAN mapping on the WLAN controller to direct data traffic from a specific user to a designated VLAN.

Answer: A,B,D


NEW QUESTION # 31
While performing a manual scan of your environment using a spectrum analyzer on a laptop computer, you notice a signal in the real time FFT view. The signal is characterized by having peak power centered on channel 11 with an approximate width of 20 MHz at its peak. The signal widens to approximately 40 MHz after it has weakened by about 30 dB.
What kind of signal is displayed in the spectrum analyzer?

  • A. A low-power wideband RF attack is in progress in 2.4 GHz, causing significant 802.11 interference
  • B. An 802.11g AP operating normally in 2.4 GHz
  • C. A frequency hopping device is being used as a signal jammer in 5 GHz
  • D. An 802.11a AP operating normally in 5 GHz

Answer: B


NEW QUESTION # 32
You have been recently hired as the wireless network administrator for an organization spread across seven locations. They have deployed more than 100 APs, but they have not been managedin either an automated or manual process for more than 18 months. Given this length of time, what is one of the first things you should evaluate from a security perspective?

  • A. The VLANs in use
  • B. The channels in use
  • C. The firmware revision
  • D. The channel widths configured

Answer: C


NEW QUESTION # 33
Given: WLAN protocol analyzers can read and record many wireless frame parameters.
What parameter is needed to physically locate rogue APs with a protocol analyzer?

  • A. SSID
  • B. Noise floor
  • C. Signal strength
  • D. IP Address
  • E. RSN IE
  • F. BSSID

Answer: C


NEW QUESTION # 34
When used as part of a WLAN authentication solution, what is the role of LDAP?

  • A. A SQL compliant authentication service capable of dynamic key generation and distribution
  • B. An Authentication Server (AS) that communicates directly with, and provides authentication for, the Supplicant.
  • C. A data retrieval protocol used by an authentication service such as RADIUS
  • D. An IEEE X.500 standard compliant database that participates in the 802.1X port-based access control process
  • E. A role-based access control protocol for filtering data to/from authenticated stations.

Answer: C


NEW QUESTION # 35
What are the three roles of the 802.1X framework, as defined by the 802.1X standard, that are performed by the client STA, the AP (or WLAN controller), and the RADIUS server? (Choose 3)

  • A. Authentication Server
  • B. Authenticator
  • C. AAA Server
  • D. Enrollee
  • E. Supplicant
  • F. Control Point
  • G. Registrar

Answer: A,B,E


NEW QUESTION # 36
Given: In a security penetration exercise, a WLAN consultant obtains the WEP key of XYZ Corporation's wireless network. Demonstrating the vulnerabilities of using WEP, the consultant uses a laptop running a software AP in an attempt to hijack the authorized user's connections. XYZ's legacy network is using 802.11n APs with 802.11b, 11g, and 11n client devices.
With this setup, how can the consultant cause all of the authorized clients to establish Layer 2 connectivity with the software access point?

  • A. All WLAN clients will reassociate to the consultant's software AP if the consultant's software AP provides the same SSID on any channel with a 10 dB SNR improvement over the authorized AP.
  • B. A higher SSID priority value configured in the Beacon frames of the consultant's software AP will take priority over the SSID in the authorized AP, causing the clients to reassociate.
  • C. If the consultant's software AP broadcasts Beacon frames that advertise 802.11g data rates that are faster rates than XYZ's current 802.11b data rates, all WLAN clients will reassociate to the faster AP.
  • D. When the RF signal between the clients and the authorized AP is temporarily disrupted and the consultant's software AP is using the same SSID on a different channel than the authorized AP, the clients will reassociate to the software AP.

Answer: D


NEW QUESTION # 37
Given: One of the security risks introduced by WPA2-Personal is an attack conducted by an authorized network user who knows the passphrase. In order to decrypt other users' traffic, the attacker must obtain certain information from the 4-way handshake of the other users.
In addition to knowing the Pairwise Master Key (PMK) and the supplicant's address (SA), what other three inputs must be collected with a protocol analyzer to recreate encryption keys? (Choose 3)

  • A. Supplicant nonce
  • B. GTKSA
  • C. Authenticator nonce
  • D. Authenticator address (BSSID)
  • E. Authentication Server nonce

Answer: A,C,D


NEW QUESTION # 38
What security benefits are provided by endpoint security solution software? (Choose 3)

  • A. Can collect statistics about a user's network use and monitor network threats while they are connected
  • B. Can restrict client connections to networks with specific SSIDs and encryption types
  • C. Can be used to monitor for and prevent network attacks by nearby rogue clients or APs
  • D. Can prevent connections to networks with security settings that do not conform to company policy

Answer: A,B,D


NEW QUESTION # 39
Wireless Intrusion Prevention Systems (WIPS) are used for what purposes? (Choose 3)

  • A. Enforcing wireless network security policy
  • B. Performance monitoring and troubleshooting
  • C. Security monitoring and notification
  • D. Classifying wired client devices
  • E. Detecting and defending against eavesdropping attacks
  • F. Preventing physical carrier sense attacks

Answer: A,B,C


NEW QUESTION # 40
Given: ABC Company secures their network with WPA2-Personal authentication and AES-CCMP encryption.
What part of the 802.11 frame is always protected from eavesdroppers by this type of security?

  • A. All MPDU contents
  • B. All PSDU contents
  • C. All PPDU contents
  • D. All MSDU contents

Answer: D


NEW QUESTION # 41
......

CWSP-207 Exam Questions Get Updated [2024] with Correct Answers: https://www.examprepaway.com/CWNP/braindumps.CWSP-207.ete.file.html