nerdexam
GIAC

GSLC · Question #3

Victor wants to use Wireless Zero Configuration (WZC) to establish a wireless network connection using his computer running on Windows XP operating system. Which of the following are the most likely…

The correct answer is B. Information of probing for networks can be viewed using a wireless analyzer and may be used to C. Attacker by creating a fake wireless network with high power antenna cause Victor's computer to. WZC on Windows XP automatically broadcasts probe requests for known networks and auto-connects to the strongest matching signal, creating two distinct attack surfaces exploitable by passive analyzers and rogue access points.

Security Architecture & Engineering

Question

Victor wants to use Wireless Zero Configuration (WZC) to establish a wireless network connection using his computer running on Windows XP operating system. Which of the following are the most likely threats to his computer? Each correct answer represents a complete solution. Choose two.

Options

  • AAttacker can use the Ping Flood DoS attack if WZC is used.
  • BInformation of probing for networks can be viewed using a wireless analyzer and may be used to
  • CAttacker by creating a fake wireless network with high power antenna cause Victor's computer to
  • DIt will not allow the configuration of encryption and MAC filtering. Sending information is not secure

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    83% (20)
  • D
    13% (3)

Why each option

WZC on Windows XP automatically broadcasts probe requests for known networks and auto-connects to the strongest matching signal, creating two distinct attack surfaces exploitable by passive analyzers and rogue access points.

AAttacker can use the Ping Flood DoS attack if WZC is used.

A Ping Flood DoS attack is a network-layer volumetric attack unrelated to the WZC auto-discovery and connection mechanism.

BInformation of probing for networks can be viewed using a wireless analyzer and may be used toCorrect

WZC continuously broadcasts probe request frames containing the SSIDs of previously connected networks so it can auto-reconnect - a wireless protocol analyzer can passively capture these frames, revealing network names and aiding targeted attacks against Victor.

CAttacker by creating a fake wireless network with high power antenna cause Victor's computer toCorrect

Because WZC automatically associates with the strongest signal broadcasting a known SSID, an attacker can deploy a rogue access point with a high-power antenna to broadcast a familiar network name and force Victor's computer to connect to the malicious network instead of the legitimate one.

DIt will not allow the configuration of encryption and MAC filtering. Sending information is not secure

WZC does support configuring WEP encryption and MAC address filtering - this statement is factually incorrect and therefore not a valid threat description.

Concept tested: Wireless Zero Configuration rogue AP and probe exposure

Source: https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-xp/bb457044(v=technet.10)

Topics

#wireless security#WZC#rogue access point#wireless analyzer

Community Discussion

No community discussion yet for this question.

Full GSLC Practice