312-50 exam dumps

312-50 practice question 371 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 371

Single answer▪ Wireless Concepts

During an authorized wireless assessment of a corporate office, you identify an access point broadcasting the company SSID on 2.4 GHz. Client devices are actively connected, but packet captures show no WPA/WPA2 4-way handshake because no clients are reconnecting. The engagement rules prohibit deauthentication attacks or any action that disrupts users. You need to determine the most practical next step to obtain material for an offline password-cracking attempt against the wireless network.

  1. A

    Capture the RSN information elements from beacon/probe frames and use them directly to derive the PSK without a handshake

  2. B

    Wait passively for a legitimate client to reconnect and capture the WPA/WPA2 4-way handshake when it occurs

  3. C

    Force the access point to downgrade from WPA2-PSK to WEP by sending crafted management frames, then crack the WEP key from IVs

  4. D

    Use ARP poisoning on the wireless subnet to recover the WPA2 passphrase from encrypted client traffic

Show answer and explanation

Correct answer: B

Explanation

For WPA/WPA2-Personal (PSK) networks, an offline password attack requires cryptographic material that allows validation of passphrase guesses. The most common source is the 4-way handshake captured when a client authenticates or reconnects. If the rules of engagement prohibit deauthentication, the assessor should use passive monitoring and wait for a natural reconnect event. This is standard wireless assessment practice and avoids service disruption. Beacon and probe management frames expose configuration details, including RSN information, but not enough to crack the PSK by themselves. Similarly, local network attacks such as ARP poisoning do not disclose the wireless passphrase. Best-practice references include the IEEE 802.11 security model for WPA/WPA2 key establishment and common wireless assessment guidance emphasizing passive capture when disruptive attacks are out of scope.

  • A. Incorrect.

    Incorrect. Beacon and probe frames contain useful metadata such as the SSID, supported rates, and RSN capabilities, but they do not contain enough cryptographic material to validate passphrase guesses for WPA/WPA2-PSK. For an offline attack against WPA/WPA2-PSK, an assessor typically needs a captured 4-way handshake or, in some cases, a PMKID if the environment is vulnerable and the method is permitted.

  • B. Correct.

    Correct. In a non-disruptive assessment, the practical approach is to continue passive monitoring until a legitimate reconnect occurs and then capture the WPA/WPA2 4-way handshake. That handshake provides the data needed to test passphrase guesses offline against WPA/WPA2-PSK. This aligns with rules of engagement that prohibit deauthentication or other disruptive techniques.

  • C. Incorrect.

    Incorrect. An access point cannot be remotely 'forced' to downgrade from WPA2-PSK to WEP through normal crafted management traffic in the way described. Security settings such as WEP or WPA2 are configured on the AP and client profiles; they are not negotiated downward like this during association. This option reflects a common misconception based on downgrade thinking from other protocols.

  • D. Incorrect.

    Incorrect. ARP poisoning may help with man-in-the-middle attacks on a local network segment after a client is already connected, but it does not reveal the WPA2-PSK from encrypted 802.11 traffic. The wireless passphrase is not recoverable from ordinary ARP-poisoned traffic captures. Offline cracking of WPA/WPA2-PSK depends on capturing appropriate authentication material, not on intercepting post-association IP traffic alone.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam