Home > Networking Tips > Wireless Networks > Tutorial test: Identifying WLAN threats
Networking Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WIRELESS NETWORKS

Tutorial test: Identifying WLAN threats


Lisa Phifer, VP, Core Competence, Inc.
06.09.2003
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   




Test your knowledge of wireless LAN vulnerabilities with this series of multiple-choice questions. To learn more about securing your WLAN, listen to the accompanying SearchSecurity.com tutorial webcast Locking down your WLAN part 1: Identifying threats with Lisa Phifer. Also read Lisa's Executive Security Briefing, Keeping wireless intruders away.

To take the test, jot your answers down on a piece of scrap paper, then check your answers here. No peeking!

1. According to business IT administrators interviewed by Microsoft, the top barrier to WLAN deployment is currently:
a) Speed
b) Support Resources
c) Budget
d) Security

2. War drivers can be prevented from discovering wireless LANs by:
a) Disabling SSID broadcasts
b) Turning on WEP
c) Placing access points indoors
d) All of the above
e) None of the above

3. Controlling WLAN access does NOT address which threat:
a) Unauthorized Resource Consumption
b) Sniffing and Eavesdropping
c) Peer Station Intrusion
d) Internet Access Freeloaders

4. Wireless access points should be deployed:

a) Inside the perimeter firewall
b) In the firewall's demilitarized zone
c) Outside the perimeter firewall
d) On the outside or DMZ
e) On the inside or outside

5. Which of the following is FALSE about 802.11 shared key authentication:
a) Access point is not authenticated
b) Station user is not individually authenticated
c) Authentication keys are different for every station
d) Authentication keys are often static, configured manually

6. MAC address "spoofing" refers to:
a) Configuring a station's MAC addresses
b) Using the MAC address of another station
c) Corrupting a peer station's address
d) Making fun of MAC addresses

7. Rogue access points reported by a WLAN analyzer can refer to:
a) APs owned by neighbors and visitors
b) APs installed by employees without IT approval
c) APs that masquerade as legitimate APs while attacking your network
d) All of the above

8. Which of the following statements is TRUE about WEP:
a) WEP stands for Wireless Ethernet Privacy
b) WEP is enabled by default in most 802.11 products
c) WEP is harder to crack if you use dynamic keys
d) WEP is so vulnerable that it should never be used

9. Surfing the Internet over wireless exposes nothing important, because anything confidential is probably SSL-encrypted anyway:
a) True
b) False

10. The new 802.11i Temporal Key Integrity Protocol (TKIP) is stronger than the original 802.11 WEP because it:
a) Does not use authentication keys directly as encryption keys
b) Uses a longer initialization vector
c) Uses a different cipher for encryption
d) All of the above
e) Answers A and B, but not C
f) Answers B and C, but not A

11. WEP stops man-in-the-middle attacks by detecting changes made to frames in transit.
a) True
b) False

12. Denial-of-service attacks against wireless LANs that cannot be prevented with today's 802.11b products include:
a) Associate floods
b) De-authenticate floods
c) Bluetooth jamming
d) All of the above

13. According to JupiterMedia's survey, which of the following security incident occurs nearly as often as finding rogue access points:
a) Loss of confidential data
b) Clients associating with the wrong access point
c) Bandwidth theft
d) Wireless access point break-in

14. During site surveys, wireless LAN discovery should include:
a) Parking lots
b) Stairwells
c) Bathrooms
d) Floors above and below
e) All of the above

15. Which of the following NOT a common wireless LAN analyzer feature:
a) Use of 802.11 drivers to interact with the link layer
b) Track usage to report statistics and analyze patterns
c) Decode packets to display protocol headers and payload
d) Send SNMP traps to alert the network administrator

16. If a war driver discovers my wireless LAN, he can access the Internet or attack my Intranet servers using 802.11 as a vector.
a) True
b) False

Check your answers.


Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Wireless Networks
802.11s mesh networks
How to prioritize wireless traffic
Wireless security protocols -- How WPA and WPA2 work
Wireless security -- How WEP encryption works
Prevent IP address conflicts on your wireless network by managing DHCP scopes
Understanding 802.11n wireless antennas
Voice over wireless LAN deployment requires constant maintenance
Wireless WAN technologies -- an overview for network pros
WLAN troubleshooting with spectrum analyzers
Wireless network security: Controlling secondary connections

Wireless Network Implementation
Extending Wi-Fi range indoors or outside with 802.11n and WDS
Accessing printers on a LAN while connected to a WLAN.
Will different wireless card link speeds cause network latency?
Open source authenticator implementation for LANs: How is open1x an 802.1X supplicant?
How do I increase network signal strength over a large distance?
Wireless deployment tips: How Amtrak deployed Wi-Fi on its trains
Bandwidth calculations for wireless networks supporting VoIP
Linksys WAP2000 Business Access Point: Review and configuration
7/11 chain cuts out controller to lower wireless networking costs
Distributed antenna system streamlines wireless management

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
802.11a  (SearchNetworking.com)
Asynchronous Pulsed Radiated Incident Light  (SearchNetworking.com)
cognitive radio  (SearchNetworking.com)
direct sequence spread spectrum  (SearchNetworking.com)
frequency-hopping spread spectrum  (SearchNetworking.com)
phase-locked loop  (SearchNetworking.com)
radio frequency  (SearchNetworking.com)
wireless mesh network  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Networking Solutions for Business
IT Management Solutions and Services Directory.
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts