nerdexam
CompTIA

PT0-001 · Question #67

A penetration testet is attempting to capture a handshake between a client and an access point by monitoring a WPA2-PSK secured wireless network. The (ester is monitoring the correct channel tor the…

The correct answer is B. Deauthentication attack. To capture a WPA2-PSK 4-way handshake without waiting for a natural client reconnection, a tester can use a deauthentication attack to forcibly disconnect clients and trigger the handshake immediately.

Attacks and exploits

Question

A penetration testet is attempting to capture a handshake between a client and an access point by monitoring a WPA2-PSK secured wireless network. The (ester is monitoring the correct channel tor the identified network but has been unsuccessful in capturing a handshake Given this scenario, which of the following attacks would BEST assist the tester in obtaining this handshake?

Options

  • AKarma attack
  • BDeauthentication attack
  • CFragmentation attack
  • DSSID broadcast flood

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    78% (32)
  • C
    12% (5)
  • D
    7% (3)

Why each option

To capture a WPA2-PSK 4-way handshake without waiting for a natural client reconnection, a tester can use a deauthentication attack to forcibly disconnect clients and trigger the handshake immediately.

AKarma attack

A Karma attack creates a rogue access point to lure nearby clients into connecting to it, rather than forcing a handshake on the legitimate monitored network.

BDeauthentication attackCorrect

A deauthentication attack transmits forged 802.11 deauthentication frames to connected clients, forcing them to drop their association and re-authenticate with the access point. This re-authentication process generates the WPA2 4-way handshake that can be captured with tools like airodump-ng. Without this active technique, the tester must wait indefinitely for a natural authentication event.

CFragmentation attack

A fragmentation attack exploits WEP's RC4 keystream recovery to forge arbitrary packets and is not applicable to WPA2-PSK handshake capture.

DSSID broadcast flood

An SSID broadcast flood sends spoofed beacon frames to overwhelm client scanners but does not force client reauthentication or produce a capturable handshake.

Concept tested: WPA2 handshake capture via deauthentication attack

Topics

#WPA2#deauthentication attack#wireless handshake#802.11

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice