nerdexam
CWNP

CWSP-207 · Question #80

Given: John Smith uses a coffee shop's Internet hot-spot (no authentication or encryption) to transfer funds between his checking and savings accounts at his bank's website. The bank's website uses…

The correct answer is B. John uses the same username and password for banking that he does for email. John used a. See the full explanation below for the reasoning.

Question

Given: John Smith uses a coffee shop's Internet hot-spot (no authentication or encryption) to transfer funds between his checking and savings accounts at his bank's website. The bank's website uses the HTTPS protocol to protect sensitive account information. While John was using the hot-spot, a hacker was able to obtain John's bank account user ID and password and exploit this information. What likely scenario could have allowed the hacker to obtain John's bank account user ID and password?

Options

  • AJohn's bank is using an expired X.509 certificate on their web server. The certificate is on John's
  • BJohn uses the same username and password for banking that he does for email. John used a
  • CJohn accessed his corporate network with his IPSec VPN software at the wireless hot-spot. An
  • DThe bank's web server is using an X.509 certificate that is not signed by a root CA, causing the
  • EBefore connecting to the bank's website, John's association to the AP was hijacked. The attacker

How the community answered

(37 responses)
  • A
    8% (3)
  • B
    73% (27)
  • C
    14% (5)
  • D
    3% (1)
  • E
    3% (1)

Community Discussion

No community discussion yet for this question.

Full CWSP-207 Practice