312-50 exam dumps

312-50 practice question 468 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 468

Single answer▪ Cryptanalysis

During an authorized wireless security assessment, you capture a WPA/WPA2-PSK 4-way handshake from a branch office access point. The client network uses a custom passphrase chosen by the local IT staff. You are asked to determine the most practical next step to recover the pre-shared key without interacting further with the target network. Which action is the best choice?

  1. A

    Perform an offline dictionary/brute-force attack against the captured handshake using candidate passwords

  2. B

    Use a chosen-plaintext attack against the access point to force it to reveal the pre-shared key directly

  3. C

    Exploit the RC4 stream cipher used by WPA2-PSK to recover the session key from the handshake capture

  4. D

    Replay the captured handshake to the access point so it decrypts and returns the original passphrase

Show answer and explanation

Correct answer: A

Explanation

The most effective and realistic cryptanalysis technique in this scenario is an offline dictionary or brute-force attack against the captured WPA/WPA2-PSK 4-way handshake. In a pre-shared key deployment, the security of the network depends heavily on passphrase strength. After capturing the handshake, a tester can validate password guesses offline by deriving the PMK using PBKDF2, deriving the PTK from the handshake values, and checking whether the computed MIC matches the captured one. This is why weak or predictable PSKs are vulnerable even when strong cryptographic primitives are used. This aligns with practical wireless assessment methodology and with guidance from standards documentation around IEEE 802.11i/WPA2 operations and industry best practices recommending strong, high-entropy passphrases or migration to enterprise authentication such as WPA2-Enterprise/WPA3.

  • A. Correct.

    Correct. In WPA/WPA2-PSK, once a valid 4-way handshake is captured, an attacker can perform an offline password-guessing attack by testing candidate passphrases. Each guess is used to derive the Pairwise Master Key (PMK), then the Pairwise Transient Key (PTK), and validate the Message Integrity Code (MIC) in the handshake. This is a classic practical cryptanalysis workflow because it allows password recovery without continued interaction with the target network.

  • B. Incorrect.

    Incorrect. A chosen-plaintext attack is not a practical method for forcing a WPA/WPA2-PSK access point to disclose the pre-shared key. The protocol does not provide a mechanism where submitting chosen plaintext causes the AP to reveal the PSK. This option reflects a misunderstanding of cryptanalytic attack models versus actual protocol behavior.

  • C. Incorrect.

    Incorrect. WPA2-PSK uses CCMP based on AES, not RC4. RC4 is associated with older WEP and WPA/TKIP-related contexts, not WPA2-CCMP. Additionally, even where weak ciphers are involved, the 4-way handshake itself is typically attacked through offline key guessing, not by directly recovering the PSK from the handshake through RC4 analysis.

  • D. Incorrect.

    Incorrect. Replaying the handshake does not cause the access point to return the original passphrase. The handshake proves possession of keying material and negotiates transient keys; it does not contain the PSK in recoverable form. This option is plausible because replay attacks are relevant in some wireless scenarios, but they do not decrypt or disclose the passphrase here.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam