nerdexam
GAQM

CPEH-001 · Question #1034

An attacker identified that a user and an access point are both compatible with WPA2 and WPA3 encryption. The attacker installed a rogue access point with only WPA2 compatibility in the vicinity and…

The correct answer is C. Downgrade security attack. Downgrade Security Attacks To launch this attack, the client and AP should support both WPA3 and WPA2 encryption mechanisms. Here, the attacker forces the user to follow the older encryption method, WPA2, to connect to the network. Here is one way to implement a downgrade…

Wireless Network Hacking

Question

An attacker identified that a user and an access point are both compatible with WPA2 and WPA3 encryption. The attacker installed a rogue access point with only WPA2 compatibility in the vicinity and forced the victim to go through the WPA2 four-way handshake to get connected. After the connection was established, the attacker used automated tools to crack WPA2-encrypted messages. What is the attack performed in the above scenario?

Options

  • ATiming-based attack
  • BSide-channel attack
  • CDowngrade security attack
  • DCache-based attack

How the community answered

(36 responses)
  • A
    14% (5)
  • B
    8% (3)
  • C
    75% (27)
  • D
    3% (1)

Explanation

Downgrade Security Attacks To launch this attack, the client and AP should support both WPA3 and WPA2 encryption mechanisms. Here, the attacker forces the user to follow the older encryption method, WPA2, to connect to the network. Here is one way to implement a downgrade security attack: Exploiting backward compatibility: If a user and AP are compatible with both WPA2 and WPA3 encryption mechanisms, then the attacker installs a rogue AP with only WPA2 compatibility in the vicinity and forces the client to go through the four-way handshake (WPA2) to get connected. Once the connection is established, the attacker uses all the attack tools available to exploit or crack the WPA2 encryption.

Topics

#downgrade attack#WPA2 vs WPA3#rogue access point#wireless encryption

Community Discussion

No community discussion yet for this question.

Full CPEH-001 Practice