312-50 exam dumps

312-50 practice question 387 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 387

Single answer▪ Wireless Attack Countermeasures

During a wireless security assessment, a company reports that employees are frequently being disconnected from the corporate Wi-Fi and then unknowingly reconnecting to a nearby rogue access point using the same SSID. The environment currently uses WPA2-Enterprise with 802.1X authentication, but management wants the most effective countermeasure to reduce the success of this attack pattern. Which action should the security team implement first?

  1. A

    Enable Protected Management Frames (802.11w/PMF) on supported clients and access points

  2. B

    Disable SSID broadcasting so employees cannot see the corporate wireless network name

  3. C

    Increase the transmit power of legitimate access points to overpower the rogue access point

  4. D

    Change from WPA2-Enterprise to WPA2-Personal with a complex pre-shared key

Show answer and explanation

Correct answer: A

Explanation

This scenario combines two common wireless threats: deauthentication attacks and evil twin/rogue access point attacks. Attackers often send forged deauthentication or disassociation frames to force users off a legitimate network, then rely on clients to reconnect to a malicious AP advertising the same SSID. The best first countermeasure from the options is enabling Protected Management Frames (PMF/802.11w), which adds protection for specific management traffic and directly reduces the effectiveness of spoofed deauthentication frames on compatible devices.

Other controls can also help in a layered defense, such as wireless intrusion detection/prevention systems (WIDS/WIPS), strong server certificate validation in 802.1X deployments, and user awareness training to avoid credential capture from rogue networks. However, among the listed choices, PMF most directly addresses the initial forced-disconnect technique used in this scenario.

This aligns with wireless security best practices in IEEE 802.11 management frame protection guidance and Wi-Fi Alliance recommendations around modern enterprise wireless security, including WPA3-era protections and certificate validation for enterprise authentication.

  • A. Correct.

    Correct. The scenario describes a deauthentication/disassociation-based attack followed by an evil twin or rogue AP lure. Protected Management Frames (PMF), defined in IEEE 802.11w and required in WPA3 with stronger protections, helps protect certain management frames from forgery, making deauthentication attacks significantly harder on supported infrastructure and clients. This is one of the most direct countermeasures to the specific attack chain described.

  • B. Incorrect.

    Incorrect. Disabling SSID broadcast does not prevent attackers from discovering the network name because SSIDs are still exposed through client probe traffic and other wireless management activity. Hidden SSIDs also create operational issues and are not an effective defense against rogue AP or deauthentication-based attacks.

  • C. Incorrect.

    Incorrect. Increasing transmit power may improve coverage in some areas, but it does not address forged management frames or prevent users from connecting to a stronger or more attractive rogue AP. It can also create interference and RF design problems. This is not the primary countermeasure for the attack pattern described.

  • D. Incorrect.

    Incorrect. Moving from WPA2-Enterprise to WPA2-Personal would weaken enterprise access control and credential management. A strong PSK does not stop deauthentication attacks and can make the environment less secure overall by replacing per-user authentication with a shared secret.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam