312-50 exam dumps

312-50 practice question 382 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 382

Single answer▪ Wireless Hacking Tools

During an authorized wireless security assessment, you need to verify whether a client's WPA2-PSK wireless network is vulnerable to offline password cracking without causing unnecessary disruption to users. The client has provided written approval to test only the target SSID. Which tool is the most appropriate to capture the WPA/WPA2 4-way handshake for later offline analysis?

  1. A

    airodump-ng

  2. B

    Kismet

  3. C

    Reaver

  4. D

    mdk4

Show answer and explanation

Correct answer: A

Explanation

The best answer is airodump-ng because the scenario specifically asks for the most appropriate tool to capture a WPA2 4-way handshake for later offline password analysis. In standard wireless assessment methodology, airodump-ng is used to passively monitor the target channel and record the handshake when a client authenticates. If permitted within the rules of engagement, testers may pair this with a controlled deauthentication event to prompt a reconnect, but the capture itself is performed with airodump-ng. Reaver is relevant only when testing WPS, not WPA2-PSK handshake capture. Kismet is excellent for passive discovery and monitoring, but CEH-style questions usually expect airodump-ng as the direct tool for handshake capture. This matches common guidance in the Aircrack-ng documentation and standard wireless assessment practices that emphasize minimizing disruption and staying within scope.

  • A. Correct.

    Correct. airodump-ng, part of the Aircrack-ng suite, is commonly used to monitor 802.11 traffic and capture WPA/WPA2 4-way handshakes for offline analysis. In a practical assessment, the tester typically places the wireless adapter in monitor mode, listens for the target BSSID and channel, and records the handshake when a client connects or reconnects. This aligns directly with the stated goal of collecting material for offline password testing.

  • B. Incorrect.

    Incorrect. Kismet is a powerful wireless network detector, sniffer, and IDS tool that can passively discover networks, clients, and traffic. While it is useful for reconnaissance and can log wireless activity, it is not the standard tool typically selected in CEH-style workflow questions specifically for capturing and preparing WPA/WPA2 handshakes for later cracking in the same direct way as airodump-ng.

  • C. Incorrect.

    Incorrect. Reaver is primarily used to assess WPS PIN vulnerabilities on access points, not to capture WPA/WPA2 4-way handshakes for offline PSK cracking. A candidate might choose it because it is a well-known wireless attack tool, but it targets a different weakness: insecure or enabled WPS implementations.

  • D. Incorrect.

    Incorrect. mdk4 is used for generating and testing various 802.11 frames and can be involved in wireless stress or denial-of-service style testing, such as deauthentication-related activities depending on the test case. However, it is not the primary tool for capturing WPA/WPA2 handshakes. Using it would not directly satisfy the requirement to record the handshake for offline analysis.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam