CWSP-207 Sample Questions & Answers
Authentication, encryption and wireless-monitoring solutions make up half the weighting, alongside penetration testing to identify and mitigate vulnerabilities, writing WLAN security policy, and lifecycle management with capacity planning.
Launch the full CWSP-207 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Security Lifecycle Management · Understand and implement management within the security lifecycle of identify, assess, protect, and monitor
An organization is implementing a new security policy that requires quarterly audits of its wireless network. Which of the following activities falls under the 'Monitor' phase of the security lifecycle?
Show answer & explanation
Correct answer: D
The 'Monitor' phase of the security lifecycle involves ongoing observation and auditing of the network to ensure compliance and detect threats. Reviewing logs from a Wireless Intrusion Prevention System (WIPS) and a Security Information and Event Management (SIEM) system is a core monitoring activity. Developing a policy is part of 'Identify', configuring security settings is part of 'Protect', and performing risk analysis is part of 'Assess'.
- Question 2Intermediate
WLAN Security Design and Architecture · Implement authentication and security services
True or False: In an 802.1X/EAP-TLS implementation, the RADIUS server requires a copy of each client's private key to validate their identity.
Show answer & explanation
Correct answer: B
This statement is false. A fundamental principle of Public Key Infrastructure (PKI) is that the private key never leaves the client device. The client proves its identity by using its private key to process information that can only be verified by the corresponding public key, which is contained in the client's certificate. The RADIUS server validates the client's certificate (checking the signature of the Certificate Authority) and verifies the client's proof of possession of the private key, but it never sees the private key itself.
- Question 3Intermediate
WLAN Security Design and Architecture · Secure public access and/or open networks
A network engineer needs to set up a secure wireless network for a small coffee shop. The owner wants to provide encrypted access for customers but does not want to manage a complex password that needs to be written on a board. The requirements are to provide individualized encryption keys for each client session without any user interaction or pre-shared keys. Which Wi-Fi security mechanism is designed for this specific use case?
Show answer & explanation
Correct answer: C
Opportunistic Wireless Encryption (OWE), also known as Wi-Fi Certified Enhanced Open, is specifically designed to provide encryption for open (unauthenticated) networks. It uses a Diffie-Hellman key exchange during the association process to create a unique, individualized encryption key for each client session, protecting users from passive eavesdropping without requiring a password. This perfectly matches the coffee shop's requirements.
- Question 4Intermediate
Vulnerabilities, Threats, and Attacks · Select and use penetration testing tools
A security team is using Kali Linux to perform a penetration test on their corporate WLAN, which uses WPA2-Personal. They have captured the 4-way handshake. Which tool from the Aircrack-ng suite would they use to attempt an offline dictionary attack against the captured handshake to recover the PSK?
Show answer & explanation
Correct answer: D
The
aircrack-ngtool itself is used for the actual cracking of keys. After capturing the 4-way handshake (typically usingairodump-ng), the capture file is fed intoaircrack-ngalong with a wordlist (dictionary file).Aircrack-ngthen iterates through the wordlist, attempting to find the correct PSK.Airmon-ngis used to put wireless cards into monitor mode,airodump-ngis for capturing packets, andaireplay-ngis for injecting packets (e.g., to perform a deauthentication attack to force a handshake). - Question 5Advanced
WLAN Security Design and Architecture · Implement or recommend appropriate wired security configurations to support the WLAN
A large enterprise is designing a multi-tiered security architecture for its WLAN. The goal is to segment traffic from different user groups (Corporate, IoT, Guest) and apply different security policies to each. Which combination of wired-side security mechanisms is most effective for achieving this?
graph TD subgraph WLAN AP1[AP] AP2[AP] end subgraph Wired Infrastructure SW[Access Switch] FW[Firewall] AAA[RADIUS Server] end subgraph Networks CorpNet[Corporate Network] IoTNet[IoT Network] GuestNet[Guest Network] end AP1 --> SW AP2 --> SW SW --> FW SW --- AAA FW --> CorpNet FW --> IoTNet FW --> GuestNetShow answer & explanation
Correct answer: B
This is the most robust and scalable solution. Using multiple SSIDs (e.g., 'Corp', 'IoT', 'Guest') allows for different authentication and encryption settings per group. Mapping each SSID to a separate VLAN segments the traffic at Layer 2. A RADIUS server can dynamically assign users/devices to the correct VLAN based on their credentials or attributes (Role-Based Access Control). Finally, a firewall with Access Control Lists (ACLs) is essential for enforcing security policies between the VLANs, such as preventing the Guest and IoT networks from accessing the Corporate network.
- Question 6Advanced
WLAN Security Design and Architecture · Implement secure transitioning (roaming) solutions
A university is implementing 802.11r Fast BSS Transition (FT) to improve roaming performance for students using real-time applications. The implementation uses 'FT over-the-Air'. What is the key difference in the roaming process when using FT over-the-Air compared to a standard WPA2-Enterprise roam?
Show answer & explanation
Correct answer: C
The primary benefit of 802.11r FT is speed. In an 'FT over-the-Air' roam, the client exchanges the necessary security information (the 4-way handshake) with the new target AP as part of the initial management frame exchange (Authentication and Reassociation frames). This eliminates the need for a separate, time-consuming 802.1X/EAP re-authentication with the RADIUS server, drastically reducing roaming time from hundreds of milliseconds to under 50 milliseconds.
- Question 7IntermediateSelect 2
Vulnerabilities, Threats, and Attacks · Implement network monitoring to identify attacks and potential vulnerabilities
A security analyst receives an alert from the WIPS indicating a 'honeypot AP' has been detected. Which characteristics are indicative of this type of attack? (Select TWO)
Show answer & explanation
Correct answers: A, D
- Question 8Intermediate
Security Lifecycle Management · Use effective change management procedures including documentation, approval, and notifications
As part of a change management process, a network administrator is upgrading the firmware on all access points in the production environment. According to best practices for security lifecycle management, what is the most critical step to perform BEFORE deploying the firmware update to all APs?
Show answer & explanation
Correct answer: C
While notifying users and backing up configurations are important parts of the change management process, the most critical step before a widespread production deployment is to validate the change. Testing the new firmware in a controlled lab environment or on a pilot group of APs allows the administrator to identify any potential bugs, performance issues, or security vulnerabilities introduced by the update without impacting the entire organization. This validation step is crucial for risk mitigation.
- Question 9Intermediate
WLAN Security Design and Architecture · Understand the capabilities of EAP methods
A security architect needs to choose an EAP method for a new corporate WLAN. The requirements are:
- Must use certificates for server validation.
- Must support user authentication via an existing Active Directory database.
- Must NOT require deploying certificates to all client devices.
Which EAP method satisfies all these requirements?
Show answer & explanation
Correct answer: C
Protected EAP (PEAP), typically used as PEAPv0/EAP-MSCHAPv2, meets all requirements. It uses a TLS tunnel, which requires a certificate on the authentication server for clients to validate. Inside this secure tunnel, it uses a second EAP method, usually MS-CHAPv2, which authenticates users against a directory like Active Directory using usernames and passwords. This avoids the administrative overhead of deploying certificates to every client device. EAP-TLS requires client-side certificates. EAP-MD5 is insecure and doesn't use certificates. EAP-FAST is Cisco-proprietary and uses PACs instead of certificates for the tunnel.
- Question 10Intermediate
Security Policy · Write policies conforming to common practices
A Chief Information Security Officer (CISO) is reviewing the WLAN security policy. The current policy states, 'Access Points must be physically secured.' The CISO finds this statement too vague. Which of the following is the BEST rewrite to make the policy statement specific, measurable, and enforceable?
Show answer & explanation
Correct answer: C
This statement is the best rewrite because it is specific (defines locations and enclosure types), measurable (provides a height requirement), and enforceable (auditors can physically check for compliance). The other options are vague and use subjective terms like 'should', 'easily accessible', and 'strong measures', which are difficult to enforce or audit consistently.
Ready for the real thing?
The full CWSP-207 simulator has every exam-style question, timed mode, and instant scoring.