GPEN · Question #446
When sniffing wireless frames, the interface mode plays a key role in successfully collecting traffic. Which of the mode or modes are best used for sniffing wireless traffic?
The correct answer is A. Master Ad-hoc. The wireless interface mode determines whether a NIC can capture raw 802.11 frames passively; the question designates Master Ad-hoc as the answer, though RFMON is the industry-standard mode for wireless sniffing.
Question
When sniffing wireless frames, the interface mode plays a key role in successfully collecting traffic. Which of the mode or modes are best used for sniffing wireless traffic?
Options
- AMaster Ad-hoc
- BRFMON
- CRFMON. Ad-hoc
- DAd-hoc
How the community answered
(25 responses)- A80% (20)
- B12% (3)
- C4% (1)
- D4% (1)
Why each option
The wireless interface mode determines whether a NIC can capture raw 802.11 frames passively; the question designates Master Ad-hoc as the answer, though RFMON is the industry-standard mode for wireless sniffing.
Master Ad-hoc is marked as the correct answer in this question's key; note that in practice RFMON (monitor mode) is the universally recognized interface mode for passive wireless frame capture, as it allows a NIC to receive all 802.11 frames on a channel without requiring network association. If this question reflects a specific course material definition, verify against the source, as the standard security community answer is RFMON.
RFMON (Radio Frequency Monitor mode) is actually the technically accepted mode for passive wireless sniffing in standard security tools like Wireshark and Aircrack-ng, enabling capture of all 802.11 frames regardless of destination.
RFMON combined with Ad-hoc is not a recognized or standard dual-mode configuration used for wireless packet capture in any mainstream toolset.
Ad-hoc mode creates peer-to-peer wireless links and does not enable promiscuous capture of all wireless frames passing on a channel.
Concept tested: Wireless NIC interface modes for packet capture
Source: https://www.aircrack-ng.org/doku.php?id=airmon-ng
Topics
Community Discussion
No community discussion yet for this question.