
[2023年04月]更新のCWNP CWSP-206問題集とリアルな試験問題
2023年最新のCWSP-206のPDF最近更新された問題
CWSP-206試験は、無線ネットワークの設計、実装、管理を担当するITプロフェッショナルに最適です。ネットワーク管理者、セキュリティ専門家、無線エンジニア、コンサルタントを含みます。また、無線ネットワークセキュリティの知識とスキルを向上させたい個人にも適しています。
CWSP-206試験は、世界的に認められたベンダー中立の認定資格です。これは、ワイヤレス業界で高く評価され、ワイヤレスセキュリティでキャリアを進めたい専門家にとって貴重な資産と考えられています。この認定は、ワイヤレスネットワーキング技術とセキュリティの概念についてしっかりと理解している専門家を対象としています。CWSP-206試験に合格した候補者は、ワイヤレスネットワークセキュリティの専門家として認められ、雇用主から高い需要があります。
質問 # 10
ABC Company has a WLAN controller using WPA2-Enterprise with PEAPv0/MS-CHAPv2 and AES-CCMP to secure their corporate wireless data. They wish to implement a guest WLAN for guest users to have Internet access, but want to implement some security controls. The security requirements for the hotspot include:
* Cannot access corporate network resources
* Network permissions are limited to Internet access
* All stations must be authenticated
What security controls would you suggest? (Choose the single best answer.)
- A. Configure access control lists (ACLs) on the guest WLAN to control data types and destinations.
- B. Implement separate controllers for the corporate and guest WLANs.
- C. Force all guest users to use a common VPN protocol to connect.
- D. Use a WIPS to deauthenticate guest users when their station tries to associate with the corporate WLAN.
- E. Require guest users to authenticate via a captive portal HTTPS login page and place the guest WLAN and the corporate WLAN on different VLANs.
正解:E
質問 # 11
For a WIPS system to identify the location of a rogue WLAN device using location pattering (RF fingerprinting), what must be done as part of the WIPS installation?
- A. All WIPS sensors must be installed as dual-purpose (AP/sensor) devices.
- B. At least six antennas must be installed in each sector.
- C. A location chipset (GPS) must be installed with it.
- D. The RF environment must be sampled during an RF calibration process.
正解:D
質問 # 12
When monitoring APs within a LAN using a Wireless Network Management System (WNMS), what secure protocol may be used bythe WNMS to issue configuration changes to APs?
- A. TFTP
- B. SNMPv3
- C. IPSec/ESP
- D. PPTP
- E. 802.1X/EAP
正解:B
質問 # 13
You are using a utility that takes input and generates random output. For example, you can provide the input of a known word as a secret word and then also provide another known word as salt input. When you process the input it generates a secret code which is a combination of letters and numbers with case sensitivity. For what is the described utility used?
- A. Generating dynamic session keys used for IPSec VPNs.
- B. Generating PMKs that can be imported into 802.11 RSN-compatible devices.
- C. Generating GTKs for broadcast traffic encryption.
- D. Generating passwords for WLAN infrastructure equipment logins.
正解:D
質問 # 14
A WLAN protocol analyzer trace reveals the following sequence of frames (excluding the ACK frames):
* 802.11 Probe Req and 802.11 Probe Rsp
* 802.11 Auth and then another 802.11 Auth
* 802.11 Assoc Req and 802.11 Assoc Rsp
* EAPOL-KEY
* EAPOL-KEY
* EAPOL-KEY
* EAPOL-KEY
What security mechanism is being used on the WLAN?
- A. EAP-TLS
- B. 802.1X/LEAP
- C. WEP-128
- D. WPA-Enterprise
- E. WPA2-Personal
正解:E
質問 # 15
What security vulnerability may result from a lack of staging, change management, and installation procedures for WLAN infrastructure equipment?
- A. Authentication cracking of 64-bit Hex WPA-Personal PSK.
- B. AES-CCMP encryption keys may be decrypted.
- C. WIPS may not classify authorized, rogue, and neighbor APs accurately.
- D. The WLAN system may be open to RF Denial-of-Service attacks.
正解:C
質問 # 16
The following numbered items show some of the contents of each of the four frames exchanged during the
4-way handshake.
* Encrypted GTK sent
* Confirmation of temporal key installation
* ANonce sent from authenticator to supplicant
* SNonce sent from supplicant to authenticator, MIC included
Arrange the frames in the correct sequence beginning with the start of the 4-way handshake.
- A. 1, 2, 3, 4
- B. 2, 3, 4, 1
- C. 4, 3, 1, 2
- D. 3, 4, 1, 2
正解:D
質問 # 17
Many computer users connect to the Internet at airports, which often have 802.11n access points with a captive portal forauthentication. While using an airport hotspot with this security solution, to what type of wireless attack is a user susceptible?
- A. Wi-Fi phishing
- B. IGMP snooping
- C. UDP port redirection
- D. Management interface exploits
正解:A
質問 # 18
In an IEEE 802.11-compliant WLAN, when is the 802.1X Controlled Port placed into the unblocked state?
- A. After the 4-Way Handshake
- B. After EAP authentication is successful
- C. After Open System authentication
- D. After any Group Handshake
正解:B
質問 # 19
Which of the following are the layers of physical security? Each correct answer represents a complete solution. Choose all that apply.
- A. Environmental design
- B. Intrusion detection system
- C. Procedural access control
- D. Video monitor
正解:A、B、C
質問 # 20
Which of the following policies are considered as a good starting point while designing a wireless security policy document? Each correct answer represents a complete solution. Choose all that apply.
- A. Rogue AP policy
- B. Protocol policy
- C. Functional security policy
- D. General security policy
正解:A、C、D
質問 # 21
Your company has just completed installation of an IEEE 802.11 WLAN controller with 20 controller-based APs. The CSO has specified PEAPv0/EAP-MSCHAPv2 as the only authorized WLAN authentication mechanism. Since an LDAP-compliant user database was already in use, a RADIUS server was installed and is querying authentication requeststo the LDAP server. Where must the X.509 server certificate and private key be installed in this network?
- A. LDAP server
- B. RADIUS server
- C. Supplicant devices
- D. WLAN controller
- E. Controller-based APs
正解:B
質問 # 22
What WLAN client device behavior is exploited by an attacker during a hijacking attack?
- A. When the RF signal between a client and an access point is lost, the client will not seek to reassociate with another access point until the 120 second hold down timer has expired.
- B. As specifiedby the Wi-Fi Alliance, clients using Open System authentication must allow direct client-to-client connections, even in an infrastructure BSS.
- C. Client drivers scan for and connect to access point in the 2.4 GHz band before scanning the 5 GHz band.
- D. After the initial association and 4-way handshake, client stations and access points do not need to perform another 4-way handshake, even if connectivity is lost.
- E. When the RF signal between a client and an access point is disrupted for more than a few seconds, the client device will attempt toassociate to an access point with better signal quality.
正解:E
質問 # 23
What TKIP feature was introduced to counter the weak integrity check algorithm used in WEP?
- A. Block cipher support
- B. RC5 stream cipher
- C. 32-bit ICV (CRC-32)
- D. Michael
- E. Sequence counters
正解:D
質問 # 24
As the primary security engineer for a large corporate network, you have been asked to author a new securitypolicy for the wireless network. While most client devices support 802.1X authentication, some legacy devices still only support passphrase/PSK-based security methods. When writing the 802.11 security policy, what password-related items should be addressed?
- A. EAP-TLS must be implemented in such scenarios.
- B. Static passwords should be changed on a regular basis to minimize the vulnerabilities of a PSK-based authentication.
- C. Certificates should always be recommended instead of passwords for 802.11 client authentication.
- D. Password complexity should be maximized so that weak WEP IV attacks are prevented.
- E. MS-CHAPv2 passwords used with EAP/PEAPv0 should be stronger than typical WPA2-PSK passphrases.
正解:B
質問 # 25
ABC Company has recently installed a WLAN controller and configured it to support WPA2-Enterprise security. The administrator has configured a security profile on the WLAN controller for each groupwithin the company (Marketing, Sales, and Engineering). How are authenticated users assigned to groups so that they receive the correct security profile within the WLAN controller?
- A. The RADIUS server sends the list of authenticated users and groups to the WLAN controller as part of a
4-Way Handshake prior to user authentication. - B. The WLAN controller polls the RADIUS server for a complete list of authenticated users and groups after each user authentication.
- C. The RADIUS server forwards the request for a group attribute to an LDAP database service, and LDAP sends the group attribute to the WLAN controller.
- D. The RADIUS server sends a group name return list attribute to the WLAN controller during every successful user authentication.
正解:D
質問 # 26
In XYZ's small business, two autonomous 802.11ac APs and 12 client devices are in use with WPA2-Personal. What statement about the WLAN security of this company is true?
- A. Intruders may obtain the passphrase with an offline dictionary attack and gain network access, but will be unable to decrypt the data traffic of other users.
- B. An unauthorized WLAN user with a protocol analyzer can decode dataframes of authorized users if he captures the BSSID, client MAC address, and a user's 4-Way Handshake.
- C. A successful attack against all unicast traffic on the network would require a weak passphrase dictionary attack and the capture of the latest 4-Way Handshake for each client.
- D. An unauthorized wireless client device cannot associate, but can eavesdrop on some data because WPA2-Personal does not encrypt multicast or broadcast traffic.
- E. Because WPA2-Personal uses Open System authentication followed by a 4-Way Handshake, hijacking attacks are easily performed.
正解:C
質問 # 27
The Aircrack-ng WLAN software tool can capture and transmit modified 802.11 frames over the wirelessnetwork. It comes pre-installed on Kali Linux and some other Linux distributions. Which one of the following would not be a suitable penetration testing action taken with this tool?
- A. Probing the RADIUS server and authenticator to expose the RADIUSshared secret.
- B. Auditing the configuration and functionality of a WIPS by simulating common attack sequences.
- C. Cracking the authentication or encryption processes implemented poorly in some WLANs.
- D. Transmitting a deauthentication frame to disconnect a user from the AP.
正解:A
質問 # 28
The following numbered items show some of the contents of each of the four frames exchanged during the 4-way handshake.
1. Encrypted GTK sent
2. Confirmation of temporal key installation
3. ANonce sent from authenticator to supplicant
4. SNonce sent from supplicant to authenticator, MIC included
Arrange the frames in the correct sequence beginning with the start of the 4-way handshake.
- A. 1, 2, 3, 4
- B. 2, 3, 4, 1
- C. 4, 3, 1, 2
- D. 3, 4, 1, 2
正解:D
質問 # 29
You work as a Network Administrator for Tech Perfect Inc. The company has a secure wireless network. Since the company's wireless network is so dynamic, it requires regular auditing to maintain proper security. For this reason, you are configuring NetStumbler as a wireless auditing tool. What services can NetStumbler provide? Each correct answer represents a complete solution. Choose all that apply.
- A. Detection of unauthorized ("rogue") access points
- B. Verification of network configurations
- C. Capturing and decoding of packets
- D. Detection of causes of wireless interference
正解:A、B、D
質問 # 30
......
最新のCWSP-206合格保証される試験問題集認証サンプル問題:https://www.passtest.jp/CWNP/CWSP-206-shiken.html
CWSP-206試験合格保証最新138問題:https://drive.google.com/open?id=1hl9rSVYz83mGT10uXAjYePZz_54xffw2