
EC-CouncilCertified Penetration Testing Professional
Domain 7Objective 1
Wireless Penetration Testing CPENT Practice Questions (Page 7)
Part of the Specialized Testing and Reporting domain, which makes up ~23% of our current practice bank.
50questions here
10free pages
10concepts
Questions 31–35
- 31
During a wireless penetration test, you need to identify all access points in a facility that spans two buildings. You run airodump-ng and capture a list of BSSIDs, but you notice that some access points appear to be broadcasting on channel 6 while others are on channel 11. You also see a client station associated with an access point that has a very weak signal. What is the most reliable way to determine whether the weak-signal access point is a rogue device or a legitimate access point that is simply far away?
Select an answer first - 32
You are testing a WEP network and have captured a large number of IVs. You run aircrack-ng, but it fails to crack the key. What is the most likely reason?
Select an answer first - 33
After cracking a WPA2 passphrase and connecting to the corporate wireless network, you want to identify the network's internal structure and potential targets. Which tool is most appropriate for this post-exploitation step?
Select an answer first - 34
Which 802.11 standard operates in the 5 GHz band and provides a maximum theoretical data rate of 54 Mbps?
Select an answer first - 35
Which tool is commonly used to create a rogue access point for an evil twin attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.