Certified Wireless Security Professional (CWSP) Free Sample Questions

20 free sample questions230 in the full practice test Other version: CWSP-206(54)

Try simulator

CWSP-207 Sample Questions

  1. Question 1

    A financial services company is deploying a new 802.11ax network and must comply with PCI-DSS 4.0 requirements. The security architect is designing the authentication mechanism for corporate-owned laptops. The primary requirements are to use device-specific credentials, prevent credential sharing, and ensure the strongest possible cryptographic protection. Which authentication and EAP method combination should be implemented to meet these requirements?

    Answer and explanation

    Correct answer: C

    WPA3-Enterprise with EAP-TLS is the strongest combination. EAP-TLS uses client-side and server-side certificates for mutual authentication, providing device-specific credentials that cannot be easily shared. This meets the stringent requirements of PCI-DSS. WPA3-Personal uses a shared key, which violates the device-specific credential requirement. EAP-PEAP uses a server-side certificate but relies on username/password credentials inside the tunnel, which are weaker than certificates. OWE is designed for unauthenticated encryption on open networks, not for corporate authentication.

  2. Question 2

    During a security audit of a university campus WLAN, a penetration tester successfully executes an attack by spoofing Disassociation frames targeting a lecturer's laptop, causing it to disconnect from the network during a presentation. The network is currently using WPA2-Enterprise with CCMP/AES. Which 802.11 amendment must be enabled to mitigate this specific attack?

    Answer and explanation

    Correct answer: C

    The 802.11w amendment introduces Protected Management Frames (PMF), also known as Management Frame Protection (MFP). This feature cryptographically protects certain management frames, including Disassociation and Deauthentication frames, preventing attackers from spoofing them to launch denial-of-service attacks. 802.11r is for fast roaming, 802.11k provides radio measurement information, and 802.11e provides Quality of Service (QoS).

  3. Question 3

    A security administrator is analyzing a packet capture of a failed WPA3-SAE connection attempt. The capture shows the client and AP exchanging several Authentication frames (Commit and Confirm), but the process fails and no Association occurs. What is the most likely cause of this failure?

    Answer and explanation

    Correct answer: C

    The WPA3-SAE (Simultaneous Authentication of Equals) handshake, also known as the Dragonfly handshake, relies on both the client and the AP knowing the same pre-shared key (password). The Commit and Confirm frames are part of a key exchange process that will only succeed if both parties start with the same password. A mismatch will cause the cryptographic checks within the handshake to fail, preventing the establishment of a Pairwise Master Key (PMK) and subsequent association. SAE does not use certificates or a RADIUS server.

  4. Question 4

    Multiple answers

    A hospital is developing its WLAN security policy to comply with HIPAA. The policy must address the security of patient data (ePHI) accessed via wireless devices. Which of the following policy statements are essential to include for HIPAA compliance? (Select TWO)

    Answer and explanation

    Correct answers: A, C

  5. Question 5

    A consultant is performing a risk assessment for a retail company's guest WLAN. The company has identified that a compromise of the guest network leading to a pivot into the corporate network could result in a loss of $500,000 in data and remediation costs. Based on historical data and industry trends, such an event is estimated to occur once every ten years. What is the Annualized Loss Expectancy (ALE) for this specific risk?

    Answer and explanation

    Correct answer: B

    The Annualized Loss Expectancy (ALE) is calculated by multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO). In this scenario, the SLE is $500,000. The ARO is the frequency of the event per year, which is once every ten years, or 1/10 = 0.1. Therefore, ALE = SLE * ARO = $500,000 * 0.1 = $50,000.

  6. Question 6

    An organization is implementing a new security policy that requires quarterly audits of its wireless network. Which of the following activities falls under the 'Monitor' phase of the security lifecycle?

    Answer and explanation

    Correct answer: D

    The 'Monitor' phase of the security lifecycle involves ongoing observation and auditing of the network to ensure compliance and detect threats. Reviewing logs from a Wireless Intrusion Prevention System (WIPS) and a Security Information and Event Management (SIEM) system is a core monitoring activity. Developing a policy is part of 'Identify', configuring security settings is part of 'Protect', and performing risk analysis is part of 'Assess'.

  7. Question 7

    True or False: In an 802.1X/EAP-TLS implementation, the RADIUS server requires a copy of each client's private key to validate their identity.

    Answer and explanation

    Correct answer: B

    This statement is false. A fundamental principle of Public Key Infrastructure (PKI) is that the private key never leaves the client device. The client proves its identity by using its private key to process information that can only be verified by the corresponding public key, which is contained in the client's certificate. The RADIUS server validates the client's certificate (checking the signature of the Certificate Authority) and verifies the client's proof of possession of the private key, but it never sees the private key itself.

  8. Question 8

    A network engineer needs to set up a secure wireless network for a small coffee shop. The owner wants to provide encrypted access for customers but does not want to manage a complex password that needs to be written on a board. The requirements are to provide individualized encryption keys for each client session without any user interaction or pre-shared keys. Which Wi-Fi security mechanism is designed for this specific use case?

    Answer and explanation

    Correct answer: C

    Opportunistic Wireless Encryption (OWE), also known as Wi-Fi Certified Enhanced Open, is specifically designed to provide encryption for open (unauthenticated) networks. It uses a Diffie-Hellman key exchange during the association process to create a unique, individualized encryption key for each client session, protecting users from passive eavesdropping without requiring a password. This perfectly matches the coffee shop's requirements.

  9. Question 9

    A security team is using Kali Linux to perform a penetration test on their corporate WLAN, which uses WPA2-Personal. They have captured the 4-way handshake. Which tool from the Aircrack-ng suite would they use to attempt an offline dictionary attack against the captured handshake to recover the PSK?

    Answer and explanation

    Correct answer: D

    The aircrack-ng tool itself is used for the actual cracking of keys. After capturing the 4-way handshake (typically using airodump-ng), the capture file is fed into aircrack-ng along with a wordlist (dictionary file). Aircrack-ng then iterates through the wordlist, attempting to find the correct PSK. Airmon-ng is used to put wireless cards into monitor mode, airodump-ng is for capturing packets, and aireplay-ng is for injecting packets (e.g., to perform a deauthentication attack to force a handshake).

  10. Question 10

    A large enterprise is designing a multi-tiered security architecture for its WLAN. The goal is to segment traffic from different user groups (Corporate, IoT, Guest) and apply different security policies to each. Which combination of wired-side security mechanisms is most effective for achieving this?

    graph TD subgraph WLAN AP1[AP] AP2[AP] end subgraph Wired Infrastructure SW[Access Switch] FW[Firewall] AAA[RADIUS Server] end subgraph Networks CorpNet[Corporate Network] IoTNet[IoT Network] GuestNet[Guest Network] end AP1 --> SW AP2 --> SW SW --> FW SW --- AAA FW --> CorpNet FW --> IoTNet FW --> GuestNet
    Answer and explanation

    Correct answer: B

    This is the most robust and scalable solution. Using multiple SSIDs (e.g., 'Corp', 'IoT', 'Guest') allows for different authentication and encryption settings per group. Mapping each SSID to a separate VLAN segments the traffic at Layer 2. A RADIUS server can dynamically assign users/devices to the correct VLAN based on their credentials or attributes (Role-Based Access Control). Finally, a firewall with Access Control Lists (ACLs) is essential for enforcing security policies between the VLANs, such as preventing the Guest and IoT networks from accessing the Corporate network.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 284 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon