nerdexam
GIAC

GSLC · Question #94

Which of the following statements are true about locating rogue access points using WLAN discovery software such as NetStumbler, Kismet, or MacStumbler if you are using a Laptop integrated with…

The correct answer is A. These tools can determine the authorization status of an access point. C. These tools detect rogue access points if the victim is using IEEE 802.11 frequency bands. This question tests knowledge of WLAN discovery tools and their capabilities and limitations when detecting rogue access points. These tools passively scan 802.11 frequencies and can identify APs but cannot determine wired network attachment.

Security Operations & Incident Response Leadership

Question

Which of the following statements are true about locating rogue access points using WLAN discovery software such as NetStumbler, Kismet, or MacStumbler if you are using a Laptop integrated with Wi-Fi compliant MiniPCI card? Each correct answer represents a complete solution. Choose two.

Options

  • AThese tools can determine the authorization status of an access point.
  • BThese tools cannot detect rogue access points if the victim is using data encryption.
  • CThese tools detect rogue access points if the victim is using IEEE 802.11 frequency bands.
  • DThese tools can determine the rogue access point even when it is attached to a wired network.

How the community answered

(36 responses)
  • A
    83% (30)
  • B
    6% (2)
  • D
    11% (4)

Why each option

This question tests knowledge of WLAN discovery tools and their capabilities and limitations when detecting rogue access points. These tools passively scan 802.11 frequencies and can identify APs but cannot determine wired network attachment.

AThese tools can determine the authorization status of an access point.Correct

Tools like NetStumbler, Kismet, and MacStumbler can identify and list discovered access points, which administrators can then compare against an authorized AP list to determine authorization status.

BThese tools cannot detect rogue access points if the victim is using data encryption.

Data encryption protects the payload of transmitted frames but does not suppress 802.11 management frames such as beacons, so rogue APs remain discoverable even when encryption is enabled.

CThese tools detect rogue access points if the victim is using IEEE 802.11 frequency bands.Correct

These tools work by scanning IEEE 802.11 frequency bands for beacon frames and probe responses, so any AP broadcasting on those frequencies - including rogue ones - will be detected regardless of other configurations.

DThese tools can determine the rogue access point even when it is attached to a wired network.

WLAN discovery tools only detect wireless signals and cannot determine whether a detected AP is physically connected to a wired network, as that relationship is not exposed in the 802.11 broadcast information.

Concept tested: WLAN rogue access point detection capabilities and limitations

Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/rogue_detection.html

Topics

#rogue access points#WLAN discovery#wireless security#NetStumbler

Community Discussion

No community discussion yet for this question.

Full GSLC Practice