The Best Practice Test Preparation for the CWSP-206 Certification Exam CWSP-206 Exam Dumps, Practice Test Questions BUNDLE PACK How to Taste Success in the CWSP- 206 Exam? The extended outline of the CWSP-206 exam demands a combination of dependable self-study resources and professional assistance. Here are some worthy options: Live Training ClassesCWNP offers live training classes across the globe [...]

The Best Practice Test Preparation for the CWSP-206 Certification Exam [Q80-Q103]

Share

The Best Practice Test Preparation for the CWSP-206 Certification Exam

CWSP-206 Exam Dumps, Practice Test Questions BUNDLE PACK


How to Taste Success in the CWSP- 206 Exam?

The extended outline of the CWSP-206 exam demands a combination of dependable self-study resources and professional assistance. Here are some worthy options:

  • Live Training Classes

    CWNP offers live training classes across the globe with the help of their education partners. For instance, the course offered by NC-Expert is divided into 11 detailed modules that cover everything the candidates should know for the test. You can find the classes near you and enroll in these instructor-led programs to be guided throughout the topics hassle-free.

  • Books

    Study and Reference Guide prepared by Tom Carpenter is a good choice for individuals that prefer standard study materials like books. This material is available on Amazon in both paperback and Kindle editions. It helps one to prepare for not just exam but real security tasks and issues as well. By going through the guide, you will find the in-depth explanations of the concepts, information about current standards, graphics, and notes, as well as review questions.

  • CWSP 206 eLearning

    One more option for those aiming to study on their own is CWSP 206 eLearning. This is the right choice as it comes with comprehensive coverage of the tested objectives as well as pre and post chapter quizzes. With unlimited access to the course, candidates will have an amazing preparation experience.

  • CWSP 206 Self-Paced Training Kit by CWNP

    The vendor offers an all-inclusive training kit that candidates can incorporate in their preparation process to have a hold of in-depth CWSP-206 exam content. This kit contains a study guide, exam voucher, and a practice test. One can get it at $424.99 from the official website.


CWNP CWSP-206 (CWSP Certified Wireless Security Professional) Certification Exam is designed for wireless networking professionals who are interested in gaining expertise in the field of wireless security. CWSP Certified Wireless Security Professional certification program is designed to instill a comprehensive understanding of the wireless security protocols, mechanisms, and technologies that are used to secure wireless networks. The program focuses on providing practical knowledge and hands-on experience in wireless security.

 

NEW QUESTION # 80
You work as a Network Administrator for Tech Perfect Inc. The company has a wireless LAN infrastructure. The management wants to prevent unauthorized network access to local area networks and other information assets by the wireless devices. What will you do?

  • A. Implement an ACL.
  • B. Implement a firewall.
  • C. Implement a dynamic NAT.
  • D. Implement a WIPS.

Answer: D


NEW QUESTION # 81
ABC Company is deploying an IEEE 802.11-compliant wireless security solution using 802.1X/EAP authentication. According to company policy, the security solution must prevent an eavesdropper from decrypting data frames traversing awireless connection. What security characteristic and/or component plays a role in preventing data decryption?

  • A. Encrypted Passphrase Protocol (EPP)
  • B. PLCP Cyclic Redundancy Check (CRC)
  • C. Integrity Check Value (ICV)
  • D. 4-Way Handshake
  • E. Multi-factor authentication

Answer: D


NEW QUESTION # 82
The following numbered items show some of the contents of each of the four frames exchanged during the 4-way handshake.
1. Encrypted GTK sent
2. Confirmation of temporal key installation
3. ANonce sent from authenticator to supplicant
4. SNonce sent from supplicant to authenticator, MIC included
Arrange the frames in the correct sequence beginning with the start of the 4-way handshake.

  • A. 3, 4, 1, 2
  • B. 4, 3, 1, 2
  • C. 2, 3, 4, 1
  • D. 1, 2, 3, 4

Answer: A


NEW QUESTION # 83
During 802.1X/LEAP authentication, the username is passed across the wireless medium in clear text. From a security perspective, why is this significant?

  • A. The username can be looked up in a dictionary file that lists common username/password combinations.
  • B. 4-Way Handshake nonces are based on the username in WPA and WPA2 authentication.
  • C. The username is needed for Personal Access Credential (PAC) and X.509 certificate validation.
  • D. The username is an input to the LEAPchallenge/response hash that is exploited, so the username must be known to conduct authentication cracking.

Answer: D


NEW QUESTION # 84
Which of the following are secure device management protocols? Each correct answer represents a complete solution. Choose all that apply.

  • A. SNMPv3
  • B. HTTP
  • C. HTTPS
  • D. SSH

Answer: A,C,D


NEW QUESTION # 85
The IEEE 802.11 standard defined Open System authentication as consisting of two auth frames and two assoc frames. In a WPA2-Enterprise network, what process immediately follows the 802.11 association procedure?

  • A. 802.1X/ EAPauthentication
  • B. Passphrase-to-PSK mapping
  • C. DHCP Discovery
  • D. 4-Way Handshake
  • E. Group Key Handshake
  • F. RADIUS shared secret lookup

Answer: A


NEW QUESTION # 86
Which of the following is a valid reason to avoid the use of EAP-MD5 in production WLANs?

  • A. It is not a valid EAP type.
  • B. It does not support a RADIUS server.
  • C. It does notsupport the outer identity.
  • D. It does not support mutual authentication.

Answer: D


NEW QUESTION # 87
You work as a Network Administrator for uCertify Inc.
You need to provide a secure communication between the server and the client computers of the company.
Which of the following protocols will you use to manage the communication securely?

  • A. HTTP
  • B. SSL
  • C. TCP
  • D. TLS

Answer: B,D


NEW QUESTION # 88
XYZ Company has recently installed a controller-based WLAN and is using a RADIUS server to query authentication requests to an LDAP server. XYZ maintains user-based access policies and would like to use the RADIUS server to facilitate network authorization. What RADIUS feature could be used by XYZ to assign the proper network permissions to users during authentications?

  • A. The RADIUS server can support vendor-specific attributes in the ACCESS-ACCEPT response, which can be used for user policy assignment.
  • B. RADIUS can send a DO-NOT-AUTHORIZE demand to the authenticator to prevent the STA from gaining access to specific files, but may only employ this in relation to Linux servers.
  • C. The RADIUS server can communicate with the DHCP server to issue the appropriate IP address and VLAN assignment to users.
  • D. RADIUS can reassign a client's 802.11 association to a new SSID by referencing a username-to-SSID mapping table in the LDAP user database.

Answer: A


NEW QUESTION # 89
In XYZ's small business, two autonomous 802.11ac APs and 12 client devices are in use with WPA2-Personal. What statement about the WLAN security of this company is true?

  • A. An unauthorized WLAN user with a protocol analyzer can decode dataframes of authorized users if he captures the BSSID, client MAC address, and a user's 4-Way Handshake.
  • B. An unauthorized wireless client device cannot associate, but can eavesdrop on some data because WPA2-Personal does not encrypt multicast or broadcast traffic.
  • C. A successful attack against all unicast traffic on the network would require a weak passphrase dictionary attack and the capture of the latest 4-Way Handshake for each client.
  • D. Intruders may obtain the passphrase with an offline dictionary attack and gain network access, but will be unable to decrypt the data traffic of other users.
  • E. Because WPA2-Personal uses Open System authentication followed by a 4-Way Handshake, hijacking attacks are easily performed.

Answer: C


NEW QUESTION # 90
Which of the following is a passive device that cannot be detected by a wireless intrusion detection system (WIDS)?

  • A. Protocol analyzer
  • B. MAC spoofing
  • C. Spectrum analyzer
  • D. Rogue access point

Answer: A


NEW QUESTION # 91
When monitoring APs within a LAN using a Wireless Network Management System (WNMS), what secure protocol may be used bythe WNMS to issue configuration changes to APs?

  • A. SNMPv3
  • B. 802.1X/EAP
  • C. IPSec/ESP
  • D. PPTP
  • E. TFTP

Answer: A


NEW QUESTION # 92
Which of the following encryption methods uses AES technology?

  • A. CCMP
  • B. Dynamic WEP
  • C. TKIP
  • D. Static WEP

Answer: A


NEW QUESTION # 93
ABC Company has recently installed a WLAN controller and configured it to support WPA2-Enterprise security. The administrator has configured a security profile on the WLAN controller for each groupwithin the company (Marketing, Sales, and Engineering). How are authenticated users assigned to groups so that they receive the correct security profile within the WLAN controller?

  • A. The WLAN controller polls the RADIUS server for a complete list of authenticated users and groups after each user authentication.
  • B. The RADIUS server sends the list of authenticated users and groups to the WLAN controller as part of a
    4-Way Handshake prior to user authentication.
  • C. The RADIUS server forwards the request for a group attribute to an LDAP database service, and LDAP sends the group attribute to the WLAN controller.
  • D. The RADIUS server sends a group name return list attribute to the WLAN controller during every successful user authentication.

Answer: D


NEW QUESTION # 94
You are installing 6 APs on the outside of your facility. They will be mounted at a height of 6 feet. What must you do to implement these APs in a secure manner beyond the normal indoor APimplementations? (Choose the single best answer.)

  • A. Use external antennas.
  • B. Power the APs using PoE.
  • C. Use internal antennas.
  • D. Ensure proper physical and environmental security using outdoor ruggedized APs or enclosures.

Answer: D


NEW QUESTION # 95
In a security penetration exercise, a WLAN consultant obtains the WEP key of XYZ Corporation's wireless network. Demonstrating the vulnerabilities of using WEP, the consultant uses a laptop running a software AP in an attempt to hijack the authorized user's connections. XYZ's legacy network is using 802.11n APs with 802.11b, 11g, and 11n client devices. With this setup, how can the consultant cause all of the authorized clients to establish Layer 2 connectivity with the software access point?

  • A. If the consultant's software AP broadcasts Beacon frames that advertise 802.11g data rates that are faster rates than XYZ's current 802.11b data rates, all WLAN clients will reassociate to the faster AP.
  • B. A higher SSID priority value configured in the Beacon frames of the consultant's software AP will take priority over the SSID in the authorized AP, causing the clients to reassociate.
  • C. When the RF signal between the clients and the authorized AP is temporarily disrupted and the consultant's software AP is using the same SSID on a different channel than the authorized AP, the clients will reassociate to the software AP.
  • D. All WLAN clients will reassociate to the consultant's software AP if the consultant's software AP provides the same SSID on any channel with a 10 dB SNR improvement over the authorized AP.

Answer: C


NEW QUESTION # 96
Which of the following is a wireless device that is created to allow a cracker to conduct a man-in- the-middle attack?

  • A. Rogue access point
  • B. WLAN controller
  • C. Lightweight Access Point
  • D. Protocol analyzer

Answer: A


NEW QUESTION # 97
A Web developer with your company wants to have wireless access for contractors that come in to work on various projects. The process of getting this approved takes time. So rather than wait, he has put his own wireless router attached to one of the network ports in his department.
What security risk does this present?

  • A. This circumvents network intrusion detection.
  • B. None, adding a wireless access point is a common task and not a security risk.
  • C. It is likely to increase network traffic and slow down network performance.
  • D. An unauthorized WAP is one way for hackers to get into a network.

Answer: D


NEW QUESTION # 98
Your company has just completed installation of an IEEE 802.11 WLAN controller with 20 controller-based APs. The CSO has specified PEAPv0/EAP-MSCHAPv2 as the only authorized WLAN authentication mechanism. Since an LDAP-compliant user database was already in use, a RADIUS server was installed and is querying authentication requeststo the LDAP server. Where must the X.509 server certificate and private key be installed in this network?

  • A. WLAN controller
  • B. Controller-based APs
  • C. LDAP server
  • D. Supplicant devices
  • E. RADIUS server

Answer: E


NEW QUESTION # 99
Which of the following DoS attacks affects mostly Windows computers by sending corrupt UDP packets?

  • A. Smurf
  • B. Fraggle
  • C. Ping flood
  • D. Bonk

Answer: D


NEW QUESTION # 100
You work as a Network Administrator for NetTech Inc.
The company has a Windows 2003 domain-based network.
The company has a main office and several branch offices.
You want to centralize the administration.
Therefore, you implement a Remote Authentication Dial-In Service (RADIUS) server. Each branch office supports its own Routing and Remote Access Server. You remove the default remote access policy, as you want to secure communications and implement a single policy that requires all dial-up communications to use a 40-bit encryption.
What will you do to accomplish this?
Each correct answer represents a part of the solution. Choose two.

  • A. Create a remote access policy on the Routing and Remote Access Server of each branch office.
  • B. Set the level of encryption to No Encryption in the remote access policy.
  • C. Create a remote access policy on the RADIUS server.
  • D. Set the level of encryption to Basic in the remote access policy.

Answer: C,D


NEW QUESTION # 101
As the primary security engineer for a large corporate network, you have been asked to author a new security policy for the wireless network. While most client devices support 802.1X authentication, some legacy devices still only support passphrase/PSK-based security methods.
When writing the 802.11 security policy, what password-related items should be addressed?

  • A. Static passwords should be changed on a regular basis to minimize the vulnerabilities of a PSK- based authentication.
  • B. MS-CHAPv2 passwords used with EAP/PEAPv0 should be stronger than typical WPA2-PSK passphrases.
  • C. Password complexity should be maximized so that weak WEP IV attacks are prevented.
  • D. EAP-TLS must be implemented in such scenarios.
  • E. Certificates should always be recommended instead of passwords for 802.11 client authentication.

Answer: A


NEW QUESTION # 102
In order to acquire credentials of a valid user on a public hotspot network, what attacks may be conducted?
Choose thesingle completely correct answer.

  • A. Social engineering and/or eavesdropping
  • B. RF DoS and/or physical theft
  • C. Authentication cracking and/or RF DoS
  • D. MAC denial of service and/or physical theft
  • E. Code injection and/or XSS

Answer: A


NEW QUESTION # 103
......

Prepare for the Actual CWSP Certification CWSP-206 Exam Practice Materials Collection: https://testking.guidetorrent.com/CWSP-206-dumps-questions.html