312-50 exam dumps

312-50 practice question 373 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 373

Single answer▪ Wireless Encryption

During an authorized wireless security assessment, you discover that a client’s guest Wi-Fi uses WPA2-Personal with a strong passphrase. Airodump-ng captures the 4-way handshake successfully, but repeated offline dictionary attacks fail to recover the key. The client asks which wireless encryption deployment would most effectively reduce the risk of this type of offline password-cracking attack while still using a modern Wi-Fi security standard for guest access. Which option is the BEST recommendation?

  1. A

    Migrate the guest network to WPA3-Personal using SAE instead of a WPA2-PSK passphrase

  2. B

    Keep WPA2-Personal but disable SSID broadcasting so attackers cannot capture the handshake

  3. C

    Downgrade to WEP and rotate the key weekly to limit the value of captured traffic

  4. D

    Keep WPA2-Personal and increase the beacon interval to reduce the chance of key exchange capture

Show answer and explanation

Correct answer: A

Explanation

The key issue in the scenario is that WPA2-Personal relies on a pre-shared key model where a captured 4-way handshake can be used for offline password guessing. If the password is weak, this is highly practical; if the password is strong, cracking may fail, but the attack path still exists. WPA3-Personal addresses this by replacing PSK-style authentication with SAE, which provides resistance to offline dictionary attacks and improves password-based Wi-Fi authentication. Hidden SSIDs and beacon adjustments are not cryptographic protections, and WEP is deprecated due to well-documented weaknesses. This aligns with Wi-Fi Alliance guidance on WPA3 and industry best practices that recommend moving away from WPA2-Personal where possible, especially when the goal is to reduce exposure to captured-handshake password attacks.

  • A. Correct.

    Correct. WPA3-Personal uses Simultaneous Authentication of Equals (SAE), which is designed to mitigate offline dictionary attacks that are possible against captured WPA/WPA2-PSK 4-way handshakes. An attacker can still interact with the network, but SAE does not provide the same reusable handshake material for straightforward offline cracking as WPA2-Personal does. For a guest network that still relies on password-based access, WPA3-Personal is the strongest practical recommendation among these choices.

  • B. Incorrect.

    Incorrect. Disabling SSID broadcast does not prevent an attacker from discovering the network, because the SSID still appears in management traffic such as probe requests and association frames. It also does not stop handshake capture. This is a common misconception: hidden SSIDs provide minimal security and do not address the cryptographic weakness of offline PSK guessing once handshake material is obtained.

  • C. Incorrect.

    Incorrect. WEP is obsolete and cryptographically broken. Its weaknesses allow key recovery through traffic analysis and IV-related attacks far more easily than attacking a strong WPA2 passphrase. Rotating WEP keys weekly does not compensate for the protocol’s fundamental design flaws. Recommending WEP would significantly weaken the client’s security posture.

  • D. Incorrect.

    Incorrect. Changing the beacon interval does not materially protect the authentication exchange or prevent a determined attacker from capturing connection-related frames. The 4-way handshake is triggered during client association, not by the beacon interval itself. This option confuses RF tuning and management-frame timing with encryption strength.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam