ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 13 - CWAP-404 discussion

Report
Export

Given a protocol analyzer can decrypt WPA2-PSK data packets providing the PSK and SSID are configured in the analyzer software. When performing packet capture (in a non-FT environment) which frames are required in order for PSK frame decryption to be possible?

A.
Authentication
Answers
A.
Authentication
B.
4-Way Handshake
Answers
B.
4-Way Handshake
C.
Reassociation
Answers
C.
Reassociation
D.
Probe Response
Answers
D.
Probe Response
Suggested answer: B

Explanation:

The 4-way handshake is the process that establishes the pairwise transient key (PTK) between the client and the AP in WPA2-PSK. The PTK is derived from the PSK, the SSID, and some random numbers exchanged in the handshake frames. The PTK is used to encrypt and decrypt the data frames between the client and the AP.Therefore, in order to decrypt WPA2-PSK data packets, a protocol analyzer needs to capture the 4-way handshake frames and have the PSK and SSID configured in the analyzer software12Reference:

CWAP-404 Study Guide, Chapter 3: 802.11 MAC Layer Frame Formats and Technologies, page 87

CWAP-404 Objectives, Section 3.5: Analyze security exchanges

asked 16/09/2024
Victor Cantu
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first