PT0-002 · Question #597
A penetration tester is testing a wireless network after business hours. The tester identifies WPA2-PSK as the protocol running in the wireless environment. After several deauthentication attacks…
The correct answer is B. No WPA2 handshakes are available to be intercepted after the deauthentication is broadcasted. If a penetration tester performs deauthentication attacks on a WPA2-PSK network after business hours and fails to capture a handshake, the most likely reason is that there are no active clients to re-authenticate and perform the handshake.
Question
A penetration tester is testing a wireless network after business hours. The tester identifies WPA2-PSK as the protocol running in the wireless environment. After several deauthentication attacks, the penetration tester has not been able to capture a handshake. Which of the following is the most likely reason?
Options
- AWPA2-PSK is not vulnerable to handshake capture techniques after deauthentication attacks.
- BNo WPA2 handshakes are available to be intercepted after the deauthentication is broadcasted.
- CThe antennas used on the wireless modem are not configured to transmit deauthentication
- DThe wireless modem needs to be configured to WPA2-Enterprise to perform a deauthentication
How the community answered
(54 responses)- A2% (1)
- B83% (45)
- C6% (3)
- D9% (5)
Why each option
If a penetration tester performs deauthentication attacks on a WPA2-PSK network after business hours and fails to capture a handshake, the most likely reason is that there are no active clients to re-authenticate and perform the handshake.
WPA2-PSK is indeed vulnerable to handshake capture techniques, especially after deauthentication attacks are used to force clients to re-authenticate.
A WPA2-PSK 4-way handshake is performed when a client attempts to re-authenticate with an access point. If there are no active clients connected to the wireless network (e.g., after business hours when users have left), a deauthentication attack, even if successful, will not cause any client to re-authenticate and thus no handshake will occur for the tester to capture.
The ability to transmit deauthentication frames is a function of the wireless adapter and software used by the attacker, not typically a configuration on the target wireless modem itself.
Deauthentication attacks are independent of whether the network is WPA2-PSK or WPA2-Enterprise; they are a layer 2 attack against the IEEE 802.11 standard.
Concept tested: WPA2-PSK handshake capture prerequisites
Topics
Community Discussion
No community discussion yet for this question.