Updated Dec-2023 Exam Engine for CWSP-206 Exam Free Demo & 365 Day Updates [Q30-Q53]

Share

Updated Dec-2023 Exam Engine for CWSP-206 Exam Free Demo & 365 Day Updates

Exam Passing Guarantee CWSP-206 Exam with Accurate Quastions!

NEW QUESTION # 30
Which of the following protocols uses separate control and data connections between the client and server applications?

  • A. SMTP
  • B. FTP
  • C. SCP
  • D. HTTP

Answer: B


NEW QUESTION # 31
Which of the following features of a switch helps to protect network from MAC flood and MAC spoofing?

  • A. Multi-Authentication
  • B. MAC Authentication Bypass
  • C. Quality of Service (QoS)
  • D. Port security

Answer: D


NEW QUESTION # 32
Many computer users connect to the Internet at airports, which often have 802.11n access points with a captive portal forauthentication. While using an airport hotspot with this security solution, to what type of wireless attack is a user susceptible?

  • A. Wi-Fi phishing
  • B. Management interface exploits
  • C. IGMP snooping
  • D. UDP port redirection

Answer: A


NEW QUESTION # 33
Joe's new laptop is experiencing difficulty connecting to ABC Company's 802.11 WLAN using
802.1X/EAP PEAPv0. The company's wireless network administrator assured Joe that his laptop was authorized in the WIPS management console for connectivity to ABC's network before it was given to him. The WIPS termination policy includes alarms for rogue stations, rogue APs, DoS attacks and unauthorized roaming. What is a likely reason that Joe cannot connect to the network?

  • A. An ASLEAP attack has been detected on APs to which Joe's laptop was trying to associate. The WIPS responded by disabling the APs.
  • B. Joe configured his 802.11 radio card to transmit at 100 mW to increase his SNR. The WIPS is detecting this much output power as a DoS attack.
  • C. Joe's integrated 802.11 radio is sending multiple Probe Request frames on each channel.
  • D. Joe disabled his laptop's integrated 802.11 radio and is using a personal PC card radio with a different chipset, drivers, and client utilities.

Answer: D


NEW QUESTION # 34
You are the Administrator for a corporate network.
You are concerned about denial of service attacks.
Which of the following would be the most help against Denial of Service (DOS) attacks?

  • A. Network surveys.
  • B. Stateful Packet Inspection (SPI) firewall
  • C. Honey pot
  • D. Packet filtering firewall

Answer: B


NEW QUESTION # 35
Which of the following attacks on wireless LAN is performed to shut down the wireless network?

  • A. Passive attack
  • B. Active attack
  • C. Man-in-the-middle attack
  • D. Jamming attack

Answer: D


NEW QUESTION # 36
Which of the following keys is derived by Pairwise Master Key (PMK)?

  • A. Private Key
  • B. Pairwise Transient Key
  • C. Group Temporal Key
  • D. Public Key

Answer: B


NEW QUESTION # 37
Which of the following keys is derived from Group Master Key (GMK)?

  • A. Private Key
  • B. Pairwise Transient Key
  • C. Public Key
  • D. Group Temporal Key

Answer: D


NEW QUESTION # 38
Which of the following would be the most help against Denial of Service (DOS) attacks?

  • A. Network surveys.
  • B. Stateful Packet Inspection (SPI) firewall
  • C. Honey pot
  • D. Packet filtering firewall

Answer: B


NEW QUESTION # 39
WLAN protocol analyzers can read and record many wireless frame parameters. What parameter is needed to physically locate rogue APs with a protocol analyzer?

  • A. RSN IE
  • B. SSID
  • C. Signal strength
  • D. Noise floor
  • E. BSSID
  • F. IP Address

Answer: C


NEW QUESTION # 40
Which of the following encryption methods uses AES technology?

  • A. Static WEP
  • B. CCMP
  • C. TKIP
  • D. Dynamic WEP

Answer: B


NEW QUESTION # 41
You work as a Network Administrator for Tech Perfect Inc. The company has a wireless LAN infrastructure. The management wants to prevent unauthorized network access to local area networks and other information assets by the wireless devices. What will you do?

  • A. Implement a WIPS.
  • B. Implement an ACL.
  • C. Implement a dynamic NAT.
  • D. Implement a firewall.

Answer: A


NEW QUESTION # 42
Which of the following are the three main intended goals of WEP encryption? Each correct answer represents a complete solution. Choose all that apply.

  • A. Confidentiality
  • B. Authentication
  • C. Access control
  • D. Data integrity

Answer: A,C,D


NEW QUESTION # 43
Which of the following is a passive device that cannot be detected by a wireless intrusion detection system (WIDS)?

  • A. Spectrum analyzer
  • B. Rogue access point
  • C. Protocol analyzer
  • D. MAC spoofing

Answer: C


NEW QUESTION # 44
Which of the following encryption algorithms is used by Wired Equivalent Privacy (WEP)?

  • A. RC4
  • B. TKIP
  • C. CCMP
  • D. RSA

Answer: A


NEW QUESTION # 45
In a security penetration exercise, a WLAN consultant obtains the WEP key of XYZ Corporation's wireless network. Demonstrating the vulnerabilities of using WEP, the consultant uses a laptop running a software AP in an attempt to hijack the authorized user's connections. XYZ's legacy network is using 802.11n APs with 802.11b, 11g, and 11n client devices. With this setup, how can the consultant cause all of the authorized clients to establish Layer 2 connectivity with the software access point?

  • A. A higher SSID priority value configured in the Beacon frames of the consultant's software AP will take priority over the SSID in the authorized AP, causing the clients to reassociate.
  • B. When the RF signal between the clients and the authorized AP is temporarily disrupted and the consultant's software AP is using the same SSID on a different channel than the authorized AP, the clients will reassociate to the software AP.
  • C. If the consultant's software AP broadcasts Beacon frames that advertise 802.11g data rates that are faster rates than XYZ's current 802.11b data rates, all WLAN clients will reassociate to the faster AP.
  • D. All WLAN clients will reassociate to the consultant's software AP if the consultant's software AP provides the same SSID on any channel with a 10 dB SNR improvement over the authorized AP.

Answer: B


NEW QUESTION # 46
XYZ Hospital plans to improve the security and performance of their Voice over Wi-Fi implementation and will be upgrading to 802.11n phones with 802.1X/EAP authentication. XYZ would like to support fast secure roaming for the phones and will require the ability to troubleshoot reassociations that are delayed or dropped during inter-channel roaming. What portable solution would be recommended for XYZ to troubleshoot roaming problems?

  • A. Spectrum analyzer software installed on a laptop computer.
  • B. An autonomous AP mounted on a mobile cart and configured to operate in monitor mode.
  • C. Laptop-based protocol analyzer with multiple 802.11n adapters.
  • D. WIPS sensor software installed on a laptop computer.

Answer: C


NEW QUESTION # 47
ABC Company has recently installed a WLAN controller and configured it to support WPA2- Enterprise security. The administrator has configured a security profile on the WLAN controller for each group within the company (Marketing, Sales, and Engineering). How are authenticated users assigned to groups so that they receive the correct security profile within the WLAN controller?

  • A. The RADIUS server forwards the request for a group attribute to an LDAP database service, and LDAP sends the group attribute to the WLAN controller.
  • B. The RADIUS server sends the list of authenticated users and groups to the WLAN controller as part of a 4-Way Handshake prior to user authentication.
  • C. The RADIUS server sends a group name return list attribute to the WLAN controller during every successful user authentication.
  • D. The WLAN controller polls the RADIUS server for a complete list of authenticated users and groups after each user authentication.

Answer: C


NEW QUESTION # 48
A Web developer with your company wants to have wireless access for contractors that come in to work on various projects. The process of getting this approved takes time. So rather than wait, he has put his own wireless router attached to one of the network ports in his department.
What security risk does this present?

  • A. It is likely to increase network traffic and slow down network performance.
  • B. This circumvents network intrusion detection.
  • C. An unauthorized WAP is one way for hackers to get into a network.
  • D. None, adding a wireless access point is a common task and not a security risk.

Answer: C


NEW QUESTION # 49
What policy would help mitigate the impact of peer-to-peer attacks against wireless-enabledcorporate laptop computers when the laptops are also used on public access networks such as wireless hotspots?

  • A. Require WPA2-Enterprise as the minimal WLAN security solution.
  • B. Require secure applications such as POP, HTTP, and SSH.
  • C. Require VPN software forconnectivity to the corporate network.
  • D. Require Port Address Translation (PAT) on each laptop.

Answer: C


NEW QUESTION # 50
You support a coffee shop and have recently installed a free 802.11ac wireless hotspot for the benefit of your customers. You want to minimize legal risk in the event that the hotspot is used for illegal Internet activity. What option specifies the best approach to minimize legal risk at this public hotspot while maintaining an open venue for customer Internet access?

  • A. Implement a captive portal with an acceptable use disclaimer.
  • B. Use a WIPS to monitor all traffic and deauthenticate malicious stations.
  • C. Require client STAs to have updated firewall and antivirus software.
  • D. Allow only trusted patrons to use the WLAN.
  • E. Block TCP port 25 and 80 outbound on the Internet router.
  • F. Configure WPA2-Enterprise security on the access point.

Answer: A


NEW QUESTION # 51
A networksecurity auditor is preparing to perform a comprehensive assessment of an 802.11ac network's security. What task should be performed at the beginning of the audit to maximize the auditor's ability to expose network vulnerabilities?

  • A. Identify the manufacturer of the wireless intrusion preventionsystem.
  • B. Identify the manufacturer of the wireless infrastructure hardware.
  • C. Identify the skill level of the wireless network security administrator(s).
  • D. Identify the wireless security solution(s) currently in use.
  • E. Identify the IP subnet information for each network segment.

Answer: D


NEW QUESTION # 52
A large enterprise is designing a secure, scalable, and manageable 802.11n WLAN that will support thousands of users. The enterprise will support both 802.1X/EAP-TTLS and PEAPv0/MSCHAPv2. Currently, thecompany is upgrading network servers as well and will replace their existing Microsoft IAS implementation with Microsoft NPS, querying Active Directory for user authentication. For this organization, as they update their WLAN infrastructure, what WLAN controller feature will likely be least valuable?

  • A. 802.1Q VLAN trunking
  • B. SNMPv3 support
  • C. WPA2-Enterprise authentication/encryption
  • D. Internal RADIUS server
  • E. WIPS support and integration

Answer: D


NEW QUESTION # 53
......

Exam Questions for CWSP-206 Updated Versions With Test Engine: https://www.testkingit.com/CWNP/latest-CWSP-206-exam-dumps.html

Test Engine to Practice Test for CWSP-206 Valid and Updated Dumps: https://drive.google.com/open?id=1GJDCX9GLPMqH6AnilcE2D0HdJENF0qwJ