PT0-001 · Question #67
A penetration testet is attempting to capture a handshake between a client and an access point by monitoring a WPA2-PSK secured wireless network. The (ester is monitoring the correct channel tor the…
The correct answer is B. Deauthentication attack. To capture a WPA2-PSK 4-way handshake without waiting for a natural client reconnection, a tester can use a deauthentication attack to forcibly disconnect clients and trigger the handshake immediately.
Question
A penetration testet is attempting to capture a handshake between a client and an access point by monitoring a WPA2-PSK secured wireless network. The (ester is monitoring the correct channel tor the identified network but has been unsuccessful in capturing a handshake Given this scenario, which of the following attacks would BEST assist the tester in obtaining this handshake?
Options
- AKarma attack
- BDeauthentication attack
- CFragmentation attack
- DSSID broadcast flood
How the community answered
(41 responses)- A2% (1)
- B78% (32)
- C12% (5)
- D7% (3)
Why each option
To capture a WPA2-PSK 4-way handshake without waiting for a natural client reconnection, a tester can use a deauthentication attack to forcibly disconnect clients and trigger the handshake immediately.
A Karma attack creates a rogue access point to lure nearby clients into connecting to it, rather than forcing a handshake on the legitimate monitored network.
A deauthentication attack transmits forged 802.11 deauthentication frames to connected clients, forcing them to drop their association and re-authenticate with the access point. This re-authentication process generates the WPA2 4-way handshake that can be captured with tools like airodump-ng. Without this active technique, the tester must wait indefinitely for a natural authentication event.
A fragmentation attack exploits WEP's RC4 keystream recovery to forge arbitrary packets and is not applicable to WPA2-PSK handshake capture.
An SSID broadcast flood sends spoofed beacon frames to overwhelm client scanners but does not force client reauthentication or produce a capturable handshake.
Concept tested: WPA2 handshake capture via deauthentication attack
Topics
Community Discussion
No community discussion yet for this question.