312-50 exam dumps

312-50 practice question 374 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 374

Single answer▪ Wireless Encryption

During an authorized wireless security assessment, you discover a company still uses WPA2-Personal (PSK) on its guest Wi-Fi. Management asks which wireless encryption configuration would most effectively reduce the risk of offline password-cracking attacks against captured handshakes while remaining practical for modern enterprise deployments. Which option should you recommend?

  1. A

    Migrate the guest network to WPA3-Personal using SAE instead of WPA2-PSK

  2. B

    Keep WPA2-Personal but increase the beacon interval to reduce handshake capture opportunities

  3. C

    Downgrade to WEP with 128-bit keys because longer static keys are harder to brute-force

  4. D

    Keep WPA2-Personal and hide the SSID so attackers cannot obtain material for offline cracking

Show answer and explanation

Correct answer: A

Explanation

The key issue in the scenario is mitigation of offline password-cracking risk against captured wireless authentication exchanges. With WPA2-Personal, an attacker who captures the 4-way handshake can attempt offline dictionary or brute-force attacks against weak PSKs. WPA3-Personal improves this by replacing PSK-based handshake exposure with SAE, which provides stronger resistance to offline guessing and better protection against password-based attacks. This aligns with Wi-Fi Alliance WPA3 guidance and industry best practices recommending migration from WPA2-Personal where feasible. By contrast, operational tweaks such as beacon interval changes or hidden SSIDs do not solve the cryptographic problem, and WEP is deprecated and insecure. From a CEH perspective, the correct recommendation is the one that directly addresses the attack path rather than relying on obscurity or obsolete encryption.

  • A. Correct.

    Correct. WPA3-Personal uses Simultaneous Authentication of Equals (SAE), also called the Dragonfly handshake, which is designed to resist the classic offline dictionary attacks associated with captured WPA/WPA2-PSK 4-way handshakes. In practice, this is the most appropriate recommendation when the goal is to reduce exposure to offline cracking while keeping a password-based wireless deployment model. It is widely recognized in Wi-Fi Alliance guidance and modern vendor best practices as the secure replacement for WPA2-Personal where client support exists.

  • B. Incorrect.

    Incorrect. Changing the beacon interval does not eliminate or meaningfully prevent capture of authentication-related traffic. Attackers performing a wireless assessment can still observe association/authentication events or trigger reconnects in test conditions where authorized. The misconception is that tuning RF timing parameters materially changes cryptographic exposure; it does not address the underlying weakness of pre-shared key authentication against offline guessing.

  • C. Incorrect.

    Incorrect. WEP is fundamentally broken due to design flaws in RC4 key scheduling and IV handling, and it can often be cracked quickly regardless of nominal key length. A 128-bit WEP key does not provide modern security and is far weaker than WPA2 or WPA3. This option reflects the common misunderstanding that a longer key alone compensates for a flawed protocol.

  • D. Incorrect.

    Incorrect. Hiding the SSID is not a security control for encryption strength. The SSID is still exposed in various management frames during normal operation, and concealed SSIDs do not prevent attackers from capturing traffic or attempting password attacks. This is a common but outdated misconception that obscurity improves wireless cryptographic security.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam