312-50 exam dumps

312-50 practice question 388 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 388

Single answer▪ Wireless Attack Countermeasures

During a wireless security assessment, a company discovers that employees are frequently connecting to a fraudulent access point broadcasting the same SSID as the corporate WLAN from the parking lot. The rogue AP is being used to capture client traffic and lure devices through stronger signal strength. The company asks for the most effective countermeasure that reduces the risk of clients joining the evil twin while still supporting an enterprise environment. Which action should the security team recommend?

  1. A

    Disable SSID broadcasting on the corporate access points so users must manually enter the network name

  2. B

    Deploy WPA3-Enterprise or WPA2-Enterprise with 802.1X server certificate validation enforced on client devices

  3. C

    Increase the transmit power of all corporate access points so they overpower unauthorized nearby devices

  4. D

    Filter unauthorized client MAC addresses at the access point to prevent rogue associations

  5. E

    Change the corporate wireless channel periodically to make it harder for attackers to mimic the WLAN

Show answer and explanation

Correct answer: B

Explanation

The best answer is to use enterprise authentication with proper certificate validation. Evil twin attacks work because clients often trust a familiar SSID without verifying that the network and authentication server are legitimate. In enterprise wireless environments, the recommended countermeasure is WPA3-Enterprise or WPA2-Enterprise using 802.1X/EAP with strict server certificate validation on endpoints. This aligns with Wi-Fi Alliance enterprise security guidance and widely accepted best practices from vendor hardening documentation. By contrast, controls such as hidden SSIDs, MAC filtering, transmit power adjustments, or channel changes do not provide cryptographic assurance of network identity and are ineffective against a determined attacker imitating the corporate WLAN. In practice, organizations should pair 802.1X with user training, wireless intrusion detection/prevention, and policies that prevent users from bypassing certificate warnings.

  • A. Incorrect.

    Incorrect. Hiding or disabling SSID broadcast does not prevent evil twin attacks because attackers can still discover the SSID from probe requests, association traffic, or legitimate clients. It may even encourage clients to actively probe for the hidden SSID, which can increase exposure. This is a common misconception that obscurity provides meaningful wireless security.

  • B. Correct.

    Correct. WPA3-Enterprise or WPA2-Enterprise with 802.1X provides mutual authentication when properly configured, and enforcing validation of the RADIUS/server certificate on client devices helps ensure users connect only to the legitimate enterprise network. This is one of the most effective controls against evil twin and credential-harvesting attacks in enterprise WLANs because the attacker cannot simply spoof the SSID and succeed without the trusted authentication infrastructure and valid certificates.

  • C. Incorrect.

    Incorrect. Raising AP transmit power may improve signal coverage but does not authenticate the network or stop clients from selecting a rogue AP with a stronger or more attractive signal. It can also increase interference and create RF management problems. Signal strength alone is not a reliable security control.

  • D. Incorrect.

    Incorrect. MAC filtering is weak as a primary countermeasure because MAC addresses are easily observed over the air and spoofed by attackers. It also does not stop users from associating with a rogue AP that is imitating the legitimate SSID. This option reflects a common but outdated belief that MAC filtering provides meaningful wireless protection.

  • E. Incorrect.

    Incorrect. Periodically changing channels may affect RF behavior but does not prevent an attacker from standing up an evil twin on another channel or copying the SSID and security settings. Channel selection is an operational tuning measure, not an authentication-based defense against rogue AP impersonation.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam