nerdexam
EC-Council

312-50V13 · Question #474

An attacker identified that a user and an access point are both compatible with WPA2 and WPA3 encryption. The attacker installed a rogue access point with only WPA2 compatibility in the vicinity and…

The correct answer is C. Downgrade security attack. The attacker performed a downgrade security attack by forcing a WPA3-capable client to connect using the less secure WPA2 protocol.

Submitted by dimitri_ru· Mar 6, 2026Hacking Wireless Networks

Question

An attacker identified that a user and an access point are both compatible with WPA2 and WPA3 encryption. The attacker installed a rogue access point with only WPA2 compatibility in the vicinity and forced the victim to go through the WPA2 four-way handshake to get connected. After the connection was established, the attacker used automated tools to crack WPA2-encrypted messages. What is the attack performed in the above scenario?

Options

  • ATiming-based attack
  • BSide-channel attack
  • CDowngrade security attack
  • DCache-based attack

How the community answered

(34 responses)
  • A
    9% (3)
  • B
    3% (1)
  • C
    74% (25)
  • D
    15% (5)

Why each option

The attacker performed a downgrade security attack by forcing a WPA3-capable client to connect using the less secure WPA2 protocol.

ATiming-based attack

A timing-based attack infers information based on the time taken for operations, which is not the primary mechanism of forcing a protocol downgrade.

BSide-channel attack

A side-channel attack exploits physical implementation characteristics (e.g., power consumption), not by manipulating encryption protocol negotiation.

CDowngrade security attackCorrect

A downgrade security attack involves an attacker forcing a system or connection to revert to a weaker, older, or less secure protocol or encryption standard, even when a stronger one is available. Here, the attacker exploits the dual compatibility to force WPA2, making it easier to crack.

DCache-based attack

A cache-based attack targets processor caches to extract data or exploit vulnerabilities, unrelated to forcing a downgrade in wireless encryption protocols.

Concept tested: Downgrade security attack

Source: https://www.cisco.com/c/en/us/products/wireless/white-paper-c11-742728.html

Topics

#downgrade attack#WPA2 cracking#WPA3#wireless security

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice