
EC-CouncilCertified Ethical Hacker
Domain 6Objective 2
Wireless Hacking Methodology CEH Practice Questions (Page 2)
Part of the Wireless Network Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
11concepts
Questions 6–10
- 6
A security administrator wants to locate a rogue access point that is broadcasting a legitimate corporate SSID. Which tool is best suited for physically locating the rogue AP?
Select an answer first - 7
A security consultant is testing the physical security of a corporate office. The consultant wants to demonstrate the risk of Bluetooth vulnerabilities by sending unsolicited messages to employees' smartphones to raise awareness. Which Bluetooth attack should the consultant use?
Select an answer first - 8
What is the primary purpose of wireless sniffing?
Select an answer first - 9
A security tester captures wireless traffic and observes that data frames are encrypted using TKIP. Which wireless security protocol is most likely in use?
Select an answer first - 10
A penetration tester is assessing a home network that uses WPA2 with WPS enabled. The tester wants to recover the network password. Which attack is most likely to succeed in this scenario?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.