Skip to content
ScopefileGet the app

Module 16Domain 6 of 9Wireless Network Hacking

Wireless networks: encryption, threats and countermeasures

Hacking wireless networks (CEH Module 16) is the whole of Domain 6, weighted at 5% in blueprint v5.0 as of Oct 11, 2026. Study it as three short lists: the Wi-Fi security generations from WEP to WPA3, the rogue access point family, and three Bluetooth attack names. Radio physics and tool syntax can stay off your desk.

Exam
312-50
Domain
6 of 9
Domain weight
5%
This file
~5%
Targets
17

Four generations, one direction

Wi-Fi security generations, oldest to current. Only the last one belongs in a remediation report today.
Chain from WEP to WPA to WPA2 to WPA3, with WPA3 highlighted as current.01WEPRC4, static key02WPATKIP stopgap onold hardware03WPA2Personal orEnterprise04WPA3SAE replaces thePSK exchangeChain from WEP to WPA to WPA2 to WPA3, with WPA3 highlighted as current.01WEPRC4, static key02WPATKIP stopgap on old hardware03WPA2Personal or Enterprise04WPA3SAE replaces the PSK exchange

Where Module 16 earns its 5%

Domain 6 holds a single module, so its full 5% lands on this file. The blueprint lists wireless concepts, encryption, threats, hacking methodology, tools, Bluetooth hacking, countermeasures and security tools. Encryption and threat names are the recall-heavy part. Tools matter least: know what each category of tool is for and leave the rest.

Give the generation chain one evening, then read the cipher-by-cipher breakdown in the WEP vs WPA vs WPA2 vs WPA3 comparison. After that, learn the threat vocabulary below. Antenna types, channel plans and the alphabet of 802.11 amendments are the tail: cram them in the final week if you have spare evenings, then let them go.

Personal mode and enterprise mode

Personal mode means every client proves it knows one shared secret. Enterprise mode hands authentication to 802.1X: the client (the supplicant) talks to the access point (the authenticator), which relays to an authentication server, usually RADIUS. The difference is who can be told apart afterward: with one shared secret, every client looks the same to the network.

Radio ignores property lines, so the rules of engagement name the networks and locations in scope; a neighbor's network your adapter happens to see stays untouched.

The rogue family and its neighbors

Rogue access point
An access point plugged into the organization's network without authorization, often by an employee who wanted better coverage. The danger is an unmanaged door into the wired side.
Evil twin
An attacker-run access point posing as a network the victim already trusts, so the victim's device joins it willingly and sends its traffic through the attacker.
Misassociation
A client joins the wrong network on its own, through auto-connect or an overlapping neighbor. No attacker skill needed, which is why client configuration and policy are the fix.
Ad hoc connection
Two devices linked directly with no access point in between. A laptop doing this while on the corporate network can bridge an outsider onto it.
Jamming
Radio-level denial of service: no credentials and no handshake, just noise on the channel. File it with availability attacks.
Wardriving
Mapping wireless networks while moving through an area. It is discovery; on its own it compromises nothing.

Run the wireless targets

Answer one, then read the note on every option before moving on. The notes on the wrong options teach as much as the key.

Answered 0/17Hits 0

T-01

A company replacing WPA2-PSK wants to cryptographically prevent clients from completing handshakes with rogue access points. Which implementation provides the strongest defense?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: EAP-TLS with strict certificate validation makes clients verify the network's server certificate, so a rogue AP without the trusted credential cannot complete authentication.
  2. BA captive portal authenticates users after they have already associated, so clients could still connect to a rogue AP that shows a lookalike portal.
  3. CProtected Management Frames stop forged deauthentication and disassociation frames, but they do not prove to a client that the access point itself is legitimate.
  4. DMAC filtering controls which clients the real AP accepts; it gives clients no way to verify an AP, and MAC addresses are trivially spoofed anyway.
T-02

While analyzing a wireless network, a penetration tester observes an access point rapidly sending probe responses for multiple unrelated SSIDs. What does this anomaly most likely indicate?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AMesh nodes advertise one consistent network for backhaul and do not answer probes for many unrelated network names, so this pattern is abnormal.
  2. BDeauthentication storms consist of deauth frames, not probe responses, and 802.11w is a protection against forged management frames rather than a source of them.
  3. CCorrect: a KARMA-style rogue AP answers clients' probes for remembered networks by claiming to be each one; WIPS flags it, and clients should forget unused open networks.
  4. DA WIPS mostly listens across channels and may contain rogue devices, but it does not impersonate many unrelated networks by answering client probes.
T-03

Which of the following methods is designed to avoid detection (i.e., not generate traffic that might trigger alarms) when discovering wireless networks monitored by wireless intrusion detection/prevention systems (WIDS/WIPS) or firewalls?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AMAC spoofing hides a device's identity while it still transmits frames, so it does not remove the network activity a WIDS can notice.
  2. BCorrect: passive sniffing only listens to beacons and traffic without transmitting anything, so it leaves no frames for a WIDS to detect, unlike active discovery.
  3. CFlooding probe requests is very noisy active scanning, and the burst of frames is exactly the kind of behavior WIDS/WIPS sensors are built to flag.
  4. DCapturing a WPA handshake targets a known network's authentication; it is not a discovery method, and forcing a handshake usually involves detectable activity.
T-04

A network administrator implements strict layer-4 firewall rules to protect corporate devices from rogue access points. Why is this defense ineffective against wireless management-frame spoofing?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: layer-3/4 firewalls see IP packets and ports after a device is already connected, so they never inspect 802.11 management frames, which need WIPS and PMF instead.
  2. BRogue APs do not tunnel management frames through IPsec; management frames exist only on the radio link and never become routed IP traffic.
  3. CWPA3 requires Protected Management Frames, which protect certain management frames from forgery, but this does not explain why a layer-4 firewall cannot see them.
  4. DA firewall never sees 802.11 management frames at all, so it cannot mistake them for DNS or any other IP-based application traffic.
T-05

In a corporate environment, what is the maximum speed achievable by the 802.11g wireless networking standard?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: historically, 802.11g offered up to 54 Mbps in the 2.4 GHz band using OFDM, while staying backward compatible with older 802.11b devices.
  2. B27 Mbps is not a defined maximum for any mainstream Wi-Fi standard, and real-world 802.11g throughput being lower does not change its rated maximum.
  3. C600 Mbps is the top rate of 802.11n (Wi-Fi 4) using multiple spatial streams and wider channels, a later standard than 802.11g.
  4. D11 Mbps is the maximum of 802.11b, the earlier 2.4 GHz standard that 802.11g replaced while remaining compatible with it.
T-06

An organization issues wearable BLE devices to employees. Security personnel want to prevent adversaries from passively tracking employees' physical movements. Which mitigation strategy MOST effectively addresses this specific tracking risk?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABLE Secure Connections with out-of-band pairing protects the key exchange against eavesdropping and spoofing, but a fixed device address still lets observers follow the wearer.
  2. BCorrect: BLE privacy uses resolvable private addresses that rotate regularly, so only bonded peers recognize the device and passive observers cannot link sightings to one employee.
  3. CLowering transmit power shrinks the range, but anyone within the reduced range still sees the same constant device address, so tracking remains possible.
  4. DNumeric comparison protects pairing against man-in-the-middle attacks, yet it does nothing about the static advertising address that makes passive location tracking possible.
T-07

A facility installs low-cost, legacy smart sensors that rely on pre-4.2 Bluetooth Low Energy standards. Which inherent vulnerability MOST likely affects these specific devices during the pairing process?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: pre-4.2 LE Legacy Pairing relies on a short passkey or none at all, so a recorded pairing exchange can be cracked offline; LE Secure Connections fixes this with ECDH.
  2. BLegacy BLE devices can store long-term keys after bonding, so constrained memory forcing constant re-authentication is not the defining pairing weakness of pre-4.2 BLE.
  3. CBluetooth discovery advertises device names and services, not administrative credentials, so cleartext credential broadcast is not an inherent property of the legacy standard.
  4. DPassive tracking through device addresses is a privacy issue separate from pairing, and the question asks specifically about the weakness in the pairing process.
T-08

Which wireless configuration change is entirely ineffective at stopping an attacker from performing offline cracking attacks on a captured WPA2 handshake?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AReplacing the PSK with a long random value directly raises the cost of offline guessing, so it is an effective response rather than an ineffective one.
  2. BA twenty-character minimum passphrase greatly enlarges the search space for offline guessing, making a captured handshake impractical to crack when the passphrase is well chosen.
  3. CMoving to 802.1X enterprise authentication removes the shared passphrase entirely, so there is no single PSK-derived handshake value left to crack offline.
  4. DCorrect: hiding the SSID only removes it from beacons; clients still reveal it when connecting, and the captured handshake stays exactly as crackable offline.
T-09

A corporate password policy requires a minimum of eight characters for the wireless PSK. Why is this policy insufficient against modern threat actors?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: eight characters is the bare WPA2 minimum, and modern GPU rigs guess offline so fast that short passphrases fall quickly once a handshake is captured.
  2. BPassphrase length has nothing to do with frame injection; unauthenticated management frames are addressed by Protected Management Frames, not by a longer pre-shared key.
  3. CSAE is the WPA3 handshake designed to resist offline dictionary attacks, so its weaknesses are not why a WPA2 eight-character PSK policy falls short.
  4. DAccess points never broadcast the PSK in management frames; the key is used to derive session keys and is not transmitted in plaintext at all.
T-10

A forensic investigator has captured 2.4 GB of encrypted wireless traffic from a WPA2-PSK network over a 6-hour period but does not possess the pre-shared key for decryption. What is the MAXIMUM defensible conclusion that can be drawn from this capture in a forensic report?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACredentials inside WPA2-encrypted data frames cannot be read without the key, so claiming they can be extracted would overstate what the capture supports.
  2. BReconstructing browsing activity requires decrypted payloads, which the investigator cannot obtain without the pre-shared key, so this claim is not defensible.
  3. CFrame-size statistics may hint at traffic types, but they decrypt nothing, so presenting them as a decryption method would be an indefensible forensic conclusion.
  4. DCorrect: management frames and frame headers stay unencrypted, so client MAC addresses, associations, disconnections and timing can be documented without reading any payload.
T-11

A security analyst reviews a wireless packet capture and suspects an evil twin attack. Which combination of indicators most strongly supports this hypothesis?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ADuplicate IP addresses and heavy ARP traffic point to address conflicts or ARP spoofing on the network, not to a lookalike wireless access point.
  2. BA TCP handshake followed by resets reflects transport-layer behavior such as closed ports or reset injection and says nothing about a cloned access point.
  3. CIncomplete EAPOL exchanges usually mean a failed authentication or missed frames in the capture; on their own they are not a distinctive evil twin indicator.
  4. DCorrect: the same SSID advertised from an unexpected BSSID, paired with deauthentication bursts that push clients off the real AP, is the classic evil twin signature.
T-12

What method does WPA2 encryption use to ensure robust security?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ARSA is an asymmetric algorithm used for key exchange and signatures in other protocols; WPA2 does not use it to encrypt wireless traffic.
  2. BWEP is the deprecated original Wi-Fi protocol whose RC4-based design was broken long ago; WPA2 replaced it rather than building on it.
  3. CCorrect: WPA2 mandates AES in CCMP mode for confidentiality and integrity; WPA3 keeps AES while strengthening the key exchange with SAE.
  4. DTKIP was an interim RC4-based fix from WPA and is now deprecated; WPA2 tolerates it only for legacy compatibility, which should be disabled.
T-13

A network administrator enables 802.11w Protected Management Frames (PMF). Which specific wireless attack does this configuration most effectively mitigate?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APMKID exposure comes from key-caching information in the authentication exchange, and Protected Management Frames do nothing to hide or prevent it.
  2. BA captive portal evil twin tricks users into typing credentials on a fake network; PMF protects frames on the legitimate network and cannot stop that deception.
  3. COffline dictionary attacks target the passphrase behind a captured handshake, and PMF does not change how that handshake is derived or protected.
  4. DCorrect: 802.11w cryptographically protects deauthentication and disassociation frames, so clients discard forged ones and cannot be knocked off the network to force reconnection.
T-14

What is the best defense against rogue access point attacks in an enterprise environment?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ADisabling guest networks reduces exposure, but rogue access points are unauthorized devices that can appear whether or not guest access exists.
  2. BTurning down legitimate AP power only changes coverage; it neither detects nor stops an attacker's rogue access point and may weaken the real network.
  3. CMAC filtering governs which clients a legitimate AP accepts and is easily spoofed; it cannot detect or contain an access point the organization does not control.
  4. DCorrect: a WIPS continuously monitors the radio environment, flags unknown or impersonating access points and can contain them, making it the main enterprise control against rogue APs.
T-15

What is the main vulnerability exploited in WPS PIN attacks?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThe flaw lies in how the PIN is checked, not in a weak cipher; the network protected behind WPS still uses WPA2 encryption.
  2. BCorrect: WPS checks the eight-digit PIN in two halves and the last digit is a checksum, shrinking the guess space to about 11,000, which is why defenders disable WPS.
  3. CThe PIN is not sent in plaintext; the protocol proves knowledge of each half cryptographically, but the split verification is what makes guessing feasible.
  4. DWPS does authenticate through the PIN or push button; the problem is that its PIN check reveals which half of the guess was correct.
T-16

Which of the following wireless standards is known for operating in both 2.4GHz and 5GHz frequency bands?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. A802.11z is an amendment for direct link setup between stations, not a radio standard known for dual-band operation.
  2. BCorrect: 802.11n, also called Wi-Fi 4, was the first mainstream standard able to operate in both the 2.4 GHz and 5 GHz bands.
  3. C802.11g operates only in the 2.4 GHz band, offering up to 54 Mbps while staying backward compatible with 802.11b.
  4. D802.11b operates only in the 2.4 GHz band with speeds up to 11 Mbps, so it is not a dual-band standard.
T-17

A security team wants to physically locate unauthorized rogue access points that have been plugged directly into their corporate LAN. Which operational control provides the MOST effective detection method?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AVLAN tag filtering on trunk links governs how tagged traffic moves between switches; it does not reveal which access port has an unauthorized access point plugged into it.
  2. BMAC filtering on managed controllers only affects the sanctioned wireless network, and a rogue access point is not managed by those controllers, so it never sees the filter.
  3. CCorrect: matching the BSSIDs that wireless scanning detects against the MAC addresses learned on wired switch ports points defenders to the physical port where the rogue device is connected.
  4. DBuilding a mesh network to triangulate radio signals is costly and indirect, and RF location alone does not confirm that the device is actually bridged into the wired LAN.

Bluetooth: three names to keep apart

Bluetooth attack terms by what the attacker gets
TermWhat happensData taken
BluejackingUnsolicited messages pushed to a nearby discoverable deviceNone
BluesnarfingUnauthorized reading of data such as contacts, messages or filesCopied off the device
BluebuggingRemote use of the device's functions, such as placing calls or sending messagesData plus control

The defense list is the same for all three: keep devices non-discoverable outside pairing, refuse unknown pairing requests, and keep the Bluetooth stack patched.

Defense in layers

Wireless defense stacks several controls: current-generation encryption, guest traffic segmented away from internal systems, Wi-Fi Protected Setup turned off, and client devices configured not to join unknown open networks on their own.

Phones and tablets are the clients on most of these networks, so the mobile platforms module picks up the same threats from the device side.

Wireless questions worth settling

Does WPA3 retire the older generations?

Not in practice. WPA3-Personal swaps the pre-shared key exchange for SAE, which the Wi-Fi Alliance says gives users increased protection from password guessing (wi-fi.org, checked Oct 11, 2026). WPA2 networks remain common, so learn both generations.

Why does Bluetooth sit in a Wi-Fi module?

Blueprint v5.0 lists Bluetooth hacking as its own sub-topic of Module 16, so the module covers the short-range radios a laptop or phone carries. The attack names differ from Wi-Fi's; the table above sorts them by what the attacker gets.

What carries over from the sniffing module?

Once a client sits on a hostile access point, the attacker is in the traffic path, so the interception ideas from the sniffing module apply unchanged. The wireless part is the delivery; the interception is a sniffing topic.

Sources