nerdexam
EC-Council

312-50V12 · Question #299

An attacker identified that a user and an access point are both compatible with WPA2 and WPA3 encryption. The attacker installed a rogue access point with only WPA2 compatibility in the vicinity and…

The correct answer is C. Downgrade security attack. The attack describes an attacker forcing a victim's device to connect using a less secure WPA2 protocol, despite WPA3 being available, to facilitate cracking the encryption.

Submitted by yuriko_h· Mar 4, 2026Wireless Network, Mobile, IoT, and OT Hacking

Question

An attacker identified that a user and an access point are both compatible with WPA2 and WPA3 encryption. The attacker installed a rogue access point with only WPA2 compatibility in the vicinity and forced the victim to go through the WPA2 four-way handshake to get connected. After the connection was established, the attacker used automated tools to crack WPA2-encrypted messages. What is the attack performed in the above scenario?

Options

  • ACache-based attack
  • BTiming-based attack
  • CDowngrade security attack
  • DSide-channel attack

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    8% (2)
  • C
    80% (20)
  • D
    4% (1)

Why each option

The attack describes an attacker forcing a victim's device to connect using a less secure WPA2 protocol, despite WPA3 being available, to facilitate cracking the encryption.

ACache-based attack

A cache-based attack exploits vulnerabilities related to a processor's cache memory to infer sensitive information, which is unrelated to manipulating network protocol negotiation.

BTiming-based attack

A timing-based attack infers sensitive data by measuring the time taken for certain operations to complete, which is not the method described for forcing a protocol downgrade.

CDowngrade security attackCorrect

This is a downgrade security attack because the attacker intentionally set up a rogue access point that only supported the weaker WPA2 encryption, compelling the victim's device, which was capable of WPA3, to fall back to the less secure WPA2 protocol. This manipulation allows the attacker to exploit known vulnerabilities in WPA2 that would otherwise be mitigated by WPA3.

DSide-channel attack

A side-channel attack extracts information from the physical implementation of a system (e.g., power consumption or electromagnetic emissions), rather than directly forcing a less secure cryptographic protocol.

Concept tested: Wi-Fi protocol downgrade attack

Source: https://www.wi-fi.org/discover-wi-fi/security

Topics

#downgrade attack#WPA2#WPA3#wireless security#rogue access point

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice