
PassTest CWSP-207問題集PDFで100%合格保証付き
CWSP-207ブレーン問題集でリアル試験最新問題2024年08月10日には122問題
質問 # 45
You perform a protocol capture using Wireshark and a compatible 802.11 adapter in Linux. When viewing the capture, you see an auth req frame and an auth rsp frame. Then you see an assoc req frame and an assoc rsp frame. Shortly after, you see DHCP communications and then ISAKMP protocol packets. What security solution is represented?
- A. Open 802.11 authentication with IPSec
- B. 802.1X/EAP-TTLS
- C. EAP-MD5
- D. WPA2-Personal with AES-CCMP
- E. 802.1X/PEAPv0/MS-CHAPv2
正解:A
質問 # 46
ABC Company requires the ability to identify and quickly locate rogue devices. ABC has chosen an overlay WIPS solution with sensors that use dipole antennas to perform this task. Use your knowledge of location tracking techniques to answer the question.
In what ways can this 802.11-based WIPS platform determine the location of rogue laptops or APs? (Choose
3)
- A. Trilateration of RSSI measurements
- B. Angle of Arrival (AoA)
- C. RF Fingerprinting
- D. GPS Positioning
- E. Time Difference of Arrival (TDoA)
正解:A、C、E
質問 # 47
Given: Mary has just finished troubleshooting an 802.11g network performance problem using a laptop-based WLAN protocol analyzer. The wireless network implements 802.1X/PEAP and the client devices are authenticating properly. When Mary disables the WLAN protocol analyzer, configures her laptop for PEAP authentication, and then tries to connect to the wireless network, she is unsuccessful. Before using the WLAN protocol analyzer, Mary's laptop connected to the network without any problems.
What statement indicates why Mary cannot access the network from her laptop computer?
- A. The nearby WIPS sensor categorized Mary's protocol analyzer adapter as a threat and is performing a deauthentication flood against her computer.
- B. Mary's supplicant software is using PEAPv0/EAP-MSCHAPv2, and the access point is using PEAPv1/EAP-GTC.
- C. The PEAP client's certificate was voided when the protocol analysis software assumed control of the wireless adapter.
- D. The protocol analyzer's network interface card (NIC) drivers are still loaded and do not support the version of PEAP being used.
正解:D
質問 # 48
Given: Your company has just completed installation of an IEEE 802.11 WLAN controller with 20 controller-based APs. The CSO has specified PEAPv0/EAP-MSCHAPv2 as the only authorized WLAN authentication mechanism. Since an LDAP-compliant user database was already in use, a RADIUS server was installed and is querying authentication requests to the LDAP server.
Where must the X.509 server certificate and private key be installed in this network?
- A. WLAN controller
- B. RADIUS server
- C. Supplicant devices
- D. Controller-based APs
- E. LDAP server
正解:B
質問 # 49
What drawbacks initially prevented the widespread acceptance and use of Opportunistic Key Caching (OKC)?
- A. Because OKC is not defined by any standards or certification body, client support was delayed and sporadic early on.
- B. Key exchanges during fast roams required processor-intensive cryptography, which was prohibitive for legacy devices supporting only TKIP.
- C. Sharing cached keys between controllers during inter-controller roaming created vulnerabilities that exposed the keys to attackers.
- D. The Wi-Fi Alliance continually delayed the creation of a client certification for OKC, even though it was defined by IEEE 802.11r.
正解:A
質問 # 50
You have been recently hired as the wireless network administrator for an organization spread across seven locations. They have deployed more than 100 APs, but they have not been managedin either an automated or manual process for more than 18 months. Given this length of time, what is one of the first things you should evaluate from a security perspective?
- A. The firmware revision
- B. The channel widths configured
- C. The channels in use
- D. The VLANs in use
正解:A
質問 # 51
Given: A WLAN consultant has just finished installing a WLAN controller with 15 controller-based APs. Two SSIDs with separate VLANs are configured for this network, and both VLANs are configured to use the same RADIUS server. The SSIDs are configured as follows:
SSID Blue - VLAN 10 - Lightweight EAP (LEAP) authentication - CCMP cipher suite SSID Red - VLAN 20 - PEAPv0/EAP-TLS authentication - TKIP cipher suite The consultant's computer can successfully authenticate and browse the Internet when using the Blue SSID.
The same computer cannot authenticate when using the Red SSID.
What is a possible cause of the problem?
- A. The Red VLAN does not use server certificate, but the client requires one.
- B. The TKIP cipher suite is not a valid option for PEAPv0 authentication.
- C. The client does not have a proper certificate installed for the tunneled authentication within the established TLS tunnel.
- D. The consultant does not have a valid Kerberos ID on the Blue VLAN.
正解:C
質問 # 52
Given: John Smith uses a coffee shop's Internet hot-spot (no authentication or encryption) to transfer funds between his checking and savings accounts at his bank's website. The bank's website uses the HTTPS protocol to protect sensitive account information. While John was using the hot-spot, a hacker was able to obtain John's bank account user ID and password and exploit this information.
What likely scenario could have allowed the hacker to obtain John's bank account user ID and password?
- A. Before connecting to the bank's website, John's association to the AP was hijacked. The attacker intercepted the HTTPS public encryption key from the bank's web server and has decrypted John's login credentials in near real-time.
- B. John uses the same username and password for banking that he does for email. John used a POP3 email client at the wireless hot-spot to check his email, and the user ID and password were not encrypted.
- C. John's bank is using an expired X.509 certificate on their web server. The certificate is on John's Certificate Revocation List (CRL), causing the user ID and password to be sent unencrypted.
- D. John accessed his corporate network with his IPSec VPN software at the wireless hot-spot. An IPSec VPN only encrypts data, so the user ID and password were sent in clear text. John uses the same username and password for banking that he does for his IPSec VPN software.
- E. The bank's web server is using an X.509 certificate that is not signed by a root CA, causing the user ID and password to be sent unencrypted.
正解:B
質問 # 53
Given: You manage a wireless network that services 200 wireless users. Your facility requires 20 access points, and you have installed an IEEE 802.11-compliant implementation of 802.1X/LEAP with AES-CCMP as an authentication and encryption solution.
In this configuration, the wireless network is initially susceptible to what type of attacks? (Choose 2)
- A. Offline dictionary attacks
- B. Session hijacking
- C. Encryption cracking
- D. Application eavesdropping
- E. Layer 3 peer-to-peer
- F. Layer 1 DoS
正解:A、F
質問 # 54
Given: In XYZ's small business, two autonomous 802.11ac APs and 12 client devices are in use with WPA2-Personal.
What statement about the WLAN security of this company is true?
- A. Because WPA2-Personal uses Open System authentication followed by a 4-Way Handshake, hijacking attacks are easily performed.
- B. Intruders may obtain the passphrase with an offline dictionary attack and gain network access, but will be unable to decrypt the data traffic of other users.
- C. An unauthorized WLAN user with a protocol analyzer can decode data frames of authorized users if he captures the BSSID, client MAC address, and a user's 4-Way Handshake.
- D. A successful attack against all unicast traffic on the network would require a weak passphrase dictionary attack and the capture of the latest 4-Way Handshake for each client.
- E. An unauthorized wireless client device cannot associate, but can eavesdrop on some data because WPA2-Personal does not encrypt multicast or broadcast traffic.
正解:D
質問 # 55
What policy would help mitigate the impact of peer-to-peer attacks against wireless-enabled corporate laptop computers when the laptops are also used on public access networks such as wireless hot-spots?
- A. Require secure applications such as POP, HTTP, and SSH.
- B. Require Port Address Translation (PAT) on each laptop.
- C. Require WPA2-Enterprise as the minimal WLAN security solution.
- D. Require VPN software for connectivity to the corporate network.
正解:D
質問 # 56
Given: You support a coffee shop and have recently installed a free 802.11ac wireless hot-spot for the benefit of your customers. You want to minimize legal risk in the event that the hot-spot is used for illegal Internet activity.
What option specifies the best approach to minimize legal risk at this public hot-spot while maintaining an open venue for customer Internet access?
- A. Allow only trusted patrons to use the WLAN
- B. Implement a captive portal with an acceptable use disclaimer
- C. Use a WIPS to monitor all traffic and deauthenticate malicious stations
- D. Configure WPA2-Enterprise security on the access point
- E. Require client STAs to have updated firewall and antivirus software
- F. Block TCP port 25 and 80 outbound on the Internet router
正解:B
質問 # 57
What WLAN client device behavior is exploited by an attacker during a hijacking attack?
- A. When the RF signal between a client and an access point is disrupted for more than a few seconds, the client device will attempt to associate to an access point with better signal quality.
- B. After the initial association and 4-way handshake, client stations and access points do not need to perform another 4-way handshake, even if connectivity is lost.
- C. Client drivers scan for and connect to access points in the 2.4 GHz band before scanning the 5 GHz band.
- D. When the RF signal between a client and an access point is lost, the client will not seek to reassociate with another access point until the 120 second hold down timer has expired.
- E. As specified by the Wi-Fi Alliance, clients using Open System authentication must allow direct client-to-client connections, even in an infrastructure BSS.
正解:A
質問 # 58
Given: Your network implements an 802.1X/EAP-based wireless security solution. A WLAN controller is installed and manages seven APs. FreeRADIUS is used for the RADIUS server and is installed on a dedicated server named SRV21. One example client is a MacBook Pro with 8 GB RAM.
What device functions as the 802.1X/EAP Authenticator?
- A. WLAN Controller/AP
- B. SRV21
- C. RADIUS server
- D. MacBook Pro
正解:A
質問 # 59
Given: A large enterprise is designing a secure, scalable, and manageable 802.11n WLAN that will support thousands of users. The enterprise will support both 802.1X/EAP-TTLS and PEAPv0/MSCHAPv2. Currently, the company is upgrading network servers as well and willreplace their existing Microsoft IAS implementation with Microsoft NPS, querying Active Directory for user authentication.
For this organization, as they update their WLAN infrastructure, what WLAN controller feature will likely be least valuable?
- A. SNMPv3 support
- B. Internal RADIUS server
- C. WIPS support and integration
- D. 802.1Q VLAN trunking
- E. WPA2-Enterprise authentication/encryption
正解:B
質問 # 60
......
CWSP-207問題集には100%厳密検証された問題と解答で合格保証付きもしくは全額返金:https://www.passtest.jp/CWNP/CWSP-207-shiken.html
最新CWSP-207PDF問題集リアル無料テスト本日更新です:https://drive.google.com/open?id=1Iaea-7-TUJwjA8bYCZlpjhSixlzkVu3G