312-50 exam dumps

312-50 practice question 390 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 390

Single answer▪ Wireless Security Tools

During an authorized wireless assessment of a corporate office, you discover a WPA2-PSK protected access point used by employees. The client has provided written approval to test whether weak pre-shared keys are in use, but they do not want prolonged disruption to production users. You need to capture material that can be used for an offline password attack with the least ongoing impact to the network. Which tool is the most appropriate for this task?

  1. A

    Aircrack-ng suite, using airodump-ng to capture the WPA/WPA2 4-way handshake and then testing candidate keys offline

  2. B

    Reaver, because it passively captures WPA2-PSK handshakes without interacting with the access point

  3. C

    Kismet, because it directly cracks WPA2-PSK in real time once the SSID is detected

  4. D

    NetStumbler, because it captures WPA2 handshakes and performs GPU-accelerated password recovery

Show answer and explanation

Correct answer: A

Explanation

For WPA/WPA2-PSK assessments, the practical workflow is typically: discover the target network, capture the 4-way handshake, and then perform offline key testing. The Aircrack-ng suite is widely used for this purpose, especially airodump-ng for capture and aircrack-ng for password testing. If a handshake is captured, password guessing can be performed offline, which aligns with the requirement to avoid prolonged disruption to production users. In contrast, Reaver is specific to WPS attacks and is only relevant when WPS is enabled and in scope. Kismet is valuable for passive detection and capture but is not itself a WPA2 cracker. NetStumbler is mainly a legacy discovery tool and does not fit the required task. This aligns with established wireless assessment practices and the documented roles of these tools in their respective project documentation and common CEH-aligned methodology.

  • A. Correct.

    Correct. In a WPA2-PSK assessment, the Aircrack-ng suite is a standard and appropriate choice. Airodump-ng can capture the 4-way handshake when a client connects or reconnects, and the captured handshake can then be used for an offline dictionary or brute-force attack using aircrack-ng or another compatible cracking tool. This approach minimizes ongoing disruption because the main goal is to capture the handshake and move the guessing process offline rather than continuously interacting with the access point.

  • B. Incorrect.

    Incorrect. Reaver is primarily used to attack Wi-Fi Protected Setup (WPS) PIN implementations, not to passively capture WPA2-PSK handshakes as its main function. It communicates with the target AP to exploit weaknesses in WPS if WPS is enabled. Choosing Reaver here reflects the common misconception that any wireless attack tool can be used interchangeably against WPA2-PSK. If WPS is disabled or locked down, Reaver is not the appropriate primary tool for this scenario.

  • C. Incorrect.

    Incorrect. Kismet is an excellent wireless network detector, sniffer, and IDS tool, but it does not directly crack WPA2-PSK in real time simply by seeing the SSID. It can help with discovery, passive monitoring, and packet capture, but the statement that it directly cracks WPA2-PSK is inaccurate. This distractor targets the misconception that discovery and monitoring tools are the same as password-cracking tools.

  • D. Incorrect.

    Incorrect. NetStumbler is an older wireless discovery tool mainly associated with identifying WLANs and basic network information on Windows. It is not the standard tool for capturing WPA2 4-way handshakes or performing GPU-accelerated password recovery. GPU-accelerated cracking is typically associated with tools such as Hashcat, not NetStumbler. This option combines recognizable wireless terminology in a technically incorrect way.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam