312-50 exam dumps

312-50 practice question 378 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 378

Single answer▪ Wireless Hacking Methodology

During an authorized wireless assessment, you identify a target corporate SSID using WPA2-PSK. The access point is configured not to support WPS, and there are currently no active client devices associated with it. The client wants to know the most practical next step to obtain material for an offline password attack without relying on social engineering. Which action should you take first?

  1. A

    Capture the 4-way handshake by waiting for a legitimate client to connect or by sending deauthentication frames to force a reconnect, then perform an offline PSK crack

  2. B

    Launch a pixie-dust attack against the access point because WPA2-PSK networks are vulnerable even when WPS is disabled

  3. C

    Exploit WPA2-PSK directly by deriving the pre-shared key from beacon frames without needing any client activity

  4. D

    Perform an ARP replay attack to generate enough traffic to recover the WPA2-PSK from weak IVs

Show answer and explanation

Correct answer: A

Explanation

The best answer is to capture a WPA/WPA2 authentication exchange and then perform an offline password attack. In real-world wireless hacking methodology, WPA2-PSK cannot be cracked from beacon traffic alone, and WEP-era IV collection techniques such as ARP replay do not apply. If WPS is disabled, WPS-specific attacks like pixie dust are not the right path. Industry-standard wireless assessment workflows, as reflected in tools such as Aircrack-ng and HCX-based capture methods, focus on obtaining a 4-way handshake or PMKID and then testing candidate passphrases offline. In authorized engagements, sending deauthentication frames may be used to induce a reconnect, but only when explicitly permitted because it is disruptive. This aligns with practical CEH expectations: identify the wireless protection in use, determine whether WPS is available, capture the appropriate authentication material, and then select the correct offline attack path.

  • A. Correct.

    Correct. In WPA/WPA2-PSK assessments, the standard practical methodology is to capture a valid authentication exchange, typically the 4-way handshake, and then attempt an offline dictionary or brute-force attack against the captured material. If no client is currently connecting, an assessor may wait for a natural association or, where authorized and within scope, transmit deauthentication frames to trigger a reconnect from an existing client. This is a common and realistic CEH-style wireless attack workflow.

  • B. Incorrect.

    Incorrect. Pixie-dust attacks are associated with weaknesses in certain WPS implementations, not WPA2-PSK itself. If WPS is disabled, a pixie-dust attack is generally not applicable. This option reflects a common misconception that any WPA2-PSK network can be attacked through WPS techniques regardless of configuration.

  • C. Incorrect.

    Incorrect. Beacon frames advertise network parameters such as SSID, supported rates, and security capabilities, but they do not provide enough information to derive the WPA2 pre-shared key directly. For WPA/WPA2-PSK, you typically need a captured handshake or PMKID to validate password guesses offline. This distractor targets the misunderstanding that passive discovery traffic alone reveals credentials.

  • D. Incorrect.

    Incorrect. ARP replay attacks are primarily associated with older WEP cracking methodology, where weak IV collection is relevant. WPA2-PSK does not rely on the same IV weakness model, so replaying ARP traffic will not let you recover the PSK through IV analysis. This is a classic error when confusing WEP and WPA/WPA2 attack techniques.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam