Download Certified Wireless Security Professional Exam.CWSP-207.Pass4Success.2026-10-06.41q.vcex

Vendor: CWNP
Exam Code: CWSP-207
Exam Name: Certified Wireless Security Professional Exam
Date: Oct 06, 2026
File Size: 235 KB

How to open VCEX files?

Files with VCEX extension can be opened by ProfExam Simulator.

Demo Questions

Question 1
Given: ABC Company has 20 employees and only needs one access point to cover their entire facility. Ten of ABC Company's employees have laptops with radio cards capable of only WPA security. The other ten employees have laptops with radio cards capable of WPA2 security. The network administrator wishes to secure all wireless communications (broadcast and unicast) for each laptop with its strongest supported security mechanism, but does not wish to implement a RADIUS/AAA server due to complexity.
What security implementation will allow the network administrator to achieve this goal?
  1. Implement an SSID with WPA2-Personal that allows both AES-CCMP and TKIP clients to connect.
  2. Implement an SSID with WPA-Personal that allows both AES-CCMP and TKIP clients to connect.
  3. Implement two separate SSIDs on the AP---one for WPA-Personal using TKIP and one for WPA2-Personal using AES-CCMP.
  4. Implement an SSID with WPA2-Personal that sends all broadcast traffic using AES-CCMP and unicast traffic using either TKIP or AES-CCMP.
Correct answer: C
Question 2
What drawbacks initially prevented the widespread acceptance and use of Opportunistic Key Caching (OKC)?
  1. Sharing cached keys between controllers during inter-controller roaming created vulnerabilities that exposed the keys to attackers.
  2. Because OKC is not defined by any standards or certification body, client support was delayed and sporadic early on.
  3. Key exchanges during fast roams required processor-intensive cryptography, which was prohibitive for legacy devices supporting only TKIP.
  4. The Wi-Fi Alliance continually delayed the creation of a client certification for OKC, even though it was defined by IEEE 802.11r.
Correct answer: B
Question 3
Given: During 802.1X/LEAP authentication, the username is passed across the wireless medium in clear text.
From a security perspective, why is this significant?
  1. The username is needed for Personal Access Credential (PAC) and X.509 certificate validation.
  2. The username is an input to the LEAP challenge/response hash that is exploited, so the username must be known to conduct authentication cracking.
  3. 4-Way Handshake nonces are based on the username in WPA and WPA2 authentication.
  4. The username can be looked up in a dictionary file that lists common username/password combinations.
Correct answer: B
Question 4
Which one of the following describes the correct hierarchy of 802.1X authentication key derivation?
  1. The MSK is generated from the 802.1X/EAP authentication. The PMK is derived from the MSK. The PTK is derived from the PMK, and the keys used for actual data encryption are a part of the PTK.
  2. If passphrase-based client authentication is used by the EAP type, the PMK is mapped directly from the user's passphrase. The PMK is then used during the 4-way handshake to create data encryption keys.
  3. After successful EAP authentication, the RADIUS server generates a PMK. A separate key, the MSK, is derived from the AAA key and is hashed with the PMK to create the PTK and GTK.
  4. The PMK is generated from a successful mutual EAP authentication. When mutual authentication is not used, an MSK is created. Either of these two keys may be used to derive the temporal data encryption keys during the 4-way handshake.
Correct answer: A
Question 5
Given: You are using a Wireless Aggregator utility to combine multiple packet captures. One capture exists for each of channels 1, 6 and 11. What kind of troubleshooting are you likely performing with such a tool?
  1. Wireless adapter failure analysis.
  2. Interference source location.
  3. Fast secure roaming problems.
  4. Narrowband DoS attack detection.
Correct answer: C
Question 6
Given: In XYZ's small business, two autonomous 802.11ac APs and 12 client devices are in use with WPA2-Personal.
What statement about the WLAN security of this company is true?
  1. Intruders may obtain the passphrase with an offline dictionary attack and gain network access, but will be unable to decrypt the data traffic of other users.
  2. A successful attack against all unicast traffic on the network would require a weak passphrase dictionary attack and the capture of the latest 4-Way Handshake for each client.
  3. An unauthorized wireless client device cannot associate, but can eavesdrop on some data because WPA2-Personal does not encrypt multicast or broadcast traffic.
  4. An unauthorized WLAN user with a protocol analyzer can decode data frames of authorized users if he captures the BSSID, client MAC address, and a user's 4-Way Handshake.
  5. Because WPA2-Personal uses Open System authentication followed by a 4-Way Handshake, hijacking attacks are easily performed.
Correct answer: B
Question 7
Given: John Smith uses a coffee shop's Internet hot-spot (no authentication or encryption) to transfer funds between his checking and savings accounts at his bank's website. The bank's website uses the HTTPS protocol to protect sensitive account information. While John was using the hot-spot, a hacker was able to obtain John's bank account user ID and password and exploit this information.
What likely scenario could have allowed the hacker to obtain John's bank account user ID and password?
  1. John's bank is using an expired X.509 certificate on their web server. The certificate is on John's Certificate Revocation List (CRL), causing the user ID and password to be sent unencrypted.
  2. John uses the same username and password for banking that he does for email. John used a POP3 email client at the wireless hot-spot to check his email, and the user ID and password were not encrypted.
  3. John accessed his corporate network with his IPSec VPN software at the wireless hot-spot. An IPSec VPN only encrypts data, so the user ID and password were sent in clear text. John uses the same username and password for banking that he does for his IPSec VPN software.
  4. The bank's web server is using an X.509 certificate that is not signed by a root CA, causing the user ID and password to be sent unencrypted.
  5. Before connecting to the bank's website, John's association to the AP was hijacked. The attacker intercepted the HTTPS public encryption key from the bank's web server and has decrypted John's login credentials in near real-time.
Correct answer: B
Question 8
What policy would help mitigate the impact of peer-to-peer attacks against wireless-enabled corporate laptop computers when the laptops are also used on public access networks such as wireless hot-spots?
  1. Require Port Address Translation (PAT) on each laptop.
  2. Require secure applications such as POP, HTTP, and SSH.
  3. Require VPN software for connectivity to the corporate network.
  4. Require WPA2-Enterprise as the minimal WLAN security solution.
    Topic 3, WLAN Security Design and Architecture
Correct answer: C
Question 9
Given: The Aircrack-ng WLAN software tool can capture and transmit modified 802.11 frames over the wireless network. It comes pre-installed on Kali Linux and some other Linux distributions.
What are three uses for such a tool? (Choose 3)
  1. Transmitting a deauthentication frame to disconnect a user from the AP.
  2. Auditing the configuration and functionality of a WIPS by simulating common attack sequences
  3. Probing the RADIUS server and authenticator to expose the RADIUS shared secret
  4. Cracking the authentication or encryption processes implemented poorly in some WLANs
Correct answer: A, B, D
Question 10
What disadvantage does EAP-TLS have when compared with PEAPv0 EAP/MSCHAPv2 as an 802.11 WLAN security solution?
  1. Fast/secure roaming in an 802.11 RSN is significantly longer when EAP-TLS is in use.
  2. EAP-TLS does not protect the client's username and password inside an encrypted tunnel.
  3. EAP-TLS cannot establish a secure tunnel for internal EAP authentication.
  4. EAP-TLS is supported only by Cisco wireless infrastructure and client devices.
  5. EAP-TLS requires extensive PKI use to create X.509 certificates for both the server and all clients, which increases administrative overhead.
Correct answer: E
HOW TO OPEN VCE FILES

Use VCE Exam Simulator to open VCE files
Avanaset

HOW TO OPEN VCEX FILES

Use ProfExam Simulator to open VCEX files
ProfExam Screen

ProfExam
ProfExam at a 20% markdown

You have the opportunity to purchase ProfExam at a 20% reduced price

Get Now!