nerdexam
GIAC

GPEN · Question #375

Victor wants to use Wireless Zero Configuration (WZC) to establish a wireless network connection using his computer running on Windows XP operating system. Which of the following are the most likely…

The correct answer is A. Attacker by creating a fake wireless network with high power antenna cause Victor's computer B. Information of probing for networks can be viewed using a wireless analyzer and may be used. WZC on Windows XP automatically connects to remembered networks and continuously probes for them, making computers vulnerable to rogue access points and passive wireless reconnaissance.

Vulnerability Discovery & Scanning

Question

Victor wants to use Wireless Zero Configuration (WZC) to establish a wireless network connection using his computer running on Windows XP operating system. Which of the following are the most likely threats to his computer? Each correct answer represents a complete solution. Choose two.

Options

  • AAttacker by creating a fake wireless network with high power antenna cause Victor's computer
  • BInformation of probing for networks can be viewed using a wireless analyzer and may be used
  • CAttacker can use the Ping Flood DoS attack if WZC is used.
  • DIt will not allow the configuration of encryption and MAC filtering. Sending information is not

How the community answered

(29 responses)
  • A
    83% (24)
  • C
    14% (4)
  • D
    3% (1)

Why each option

WZC on Windows XP automatically connects to remembered networks and continuously probes for them, making computers vulnerable to rogue access points and passive wireless reconnaissance.

AAttacker by creating a fake wireless network with high power antenna cause Victor's computerCorrect

An attacker can deploy a rogue access point broadcasting the SSID of a trusted network with a high-power antenna, causing WZC to automatically associate with it, exposing the user to man-in-the-middle attacks and credential theft. Because WZC selects networks based on remembered SSIDs and signal strength without mutual authentication, it cannot distinguish a legitimate AP from an evil twin.

BInformation of probing for networks can be viewed using a wireless analyzer and may be usedCorrect

WZC continuously broadcasts probe request frames containing the SSIDs of all stored preferred networks, and any nearby attacker running a wireless packet analyzer can passively capture these frames. The captured SSID list can then be used to craft targeted rogue AP attacks or to map the user's network habits.

CAttacker can use the Ping Flood DoS attack if WZC is used.

A Ping Flood DoS attack is a generic ICMP-based attack unrelated to WZC; using WZC does not introduce any additional vulnerability to ICMP flood attacks.

DIt will not allow the configuration of encryption and MAC filtering. Sending information is not

WZC does support configuration of wireless encryption such as WEP and WPA as well as MAC filtering, so the claim that it prevents these security configurations is factually incorrect.

Concept tested: WZC vulnerabilities - rogue AP and probe request exposure

Source: https://learn.microsoft.com/en-us/troubleshoot/windows-client/networking/wireless-zero-configuration-service-overview

Topics

#Wireless Zero Configuration#rogue access point#wireless probing#WZC threats

Community Discussion

No community discussion yet for this question.

Full GPEN Practice