PT0-001 · Question #137
A penetration tester is attempting to capture a handshake between a client and an access point by monitoring a WPA2-PSK secured wireless network. The tester is monitoring the correct channel for the…
The correct answer is B. Deauthentication attack. To capture a WPA2-PSK 4-way handshake, the tester must force a client to re-authenticate by sending deauthentication frames, which triggers a new handshake exchange.
Question
A penetration tester is attempting to capture a handshake between a client and an access point by monitoring a WPA2-PSK secured wireless network. The tester is monitoring the correct channel for the identified network, but has been unsuccessful in capturing a handshake. Given the scenario, which of the following attacks would BEST assist the tester in obtaining this handshake?
Options
- AKarma attack
- BDeauthentication attack
- CFragmentation attack
- DSSDI broadcast flood
How the community answered
(28 responses)- A11% (3)
- B82% (23)
- C4% (1)
- D4% (1)
Why each option
To capture a WPA2-PSK 4-way handshake, the tester must force a client to re-authenticate by sending deauthentication frames, which triggers a new handshake exchange.
A Karma attack responds to client probe requests by impersonating any requested SSID to lure clients to a rogue AP, which is an evil twin technique unrelated to capturing a legitimate WPA2 handshake.
A deauthentication attack sends spoofed 802.11 deauth frames to a connected client, forcibly disconnecting it from the access point. When the client reconnects, it performs the WPA2 4-way handshake, which the tester can then capture from the monitored channel. This is the standard technique for obtaining a handshake without waiting passively for a natural reconnection event.
A fragmentation attack exploits weaknesses in the WEP protocol to reconstruct keystreams and is not applicable to WPA2-secured networks.
An SSID broadcast flood is not a recognized standard attack technique for forcing handshake capture and would not cause a targeted client to re-authenticate to its legitimate AP.
Concept tested: Forcing WPA2 handshake capture via deauthentication
Source: https://www.aircrack-ng.org/doku.php?id=deauthentication
Topics
Community Discussion
No community discussion yet for this question.