CWSP-207 Sample Questions

CWSP-207 Sample Questions & Answers

Authentication, encryption and wireless-monitoring solutions make up half the weighting, alongside penetration testing to identify and mitigate vulnerabilities, writing WLAN security policy, and lifecycle management with capacity planning.

Launch the full CWSP-207 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Security Lifecycle Management · Understand and implement management within the security lifecycle of identify, assess, protect, and monitor

    An organization is implementing a new security policy that requires quarterly audits of its wireless network. Which of the following activities falls under the 'Monitor' phase of the security lifecycle?

    Show answer & explanation

    Correct answer: D

    The 'Monitor' phase of the security lifecycle involves ongoing observation and auditing of the network to ensure compliance and detect threats. Reviewing logs from a Wireless Intrusion Prevention System (WIPS) and a Security Information and Event Management (SIEM) system is a core monitoring activity. Developing a policy is part of 'Identify', configuring security settings is part of 'Protect', and performing risk analysis is part of 'Assess'.

  2. Question 2Intermediate

    WLAN Security Design and Architecture · Implement authentication and security services

    True or False: In an 802.1X/EAP-TLS implementation, the RADIUS server requires a copy of each client's private key to validate their identity.

    Show answer & explanation

    Correct answer: B

    This statement is false. A fundamental principle of Public Key Infrastructure (PKI) is that the private key never leaves the client device. The client proves its identity by using its private key to process information that can only be verified by the corresponding public key, which is contained in the client's certificate. The RADIUS server validates the client's certificate (checking the signature of the Certificate Authority) and verifies the client's proof of possession of the private key, but it never sees the private key itself.

  3. Question 3Intermediate

    WLAN Security Design and Architecture · Secure public access and/or open networks

    A network engineer needs to set up a secure wireless network for a small coffee shop. The owner wants to provide encrypted access for customers but does not want to manage a complex password that needs to be written on a board. The requirements are to provide individualized encryption keys for each client session without any user interaction or pre-shared keys. Which Wi-Fi security mechanism is designed for this specific use case?

    Show answer & explanation

    Correct answer: C

    Opportunistic Wireless Encryption (OWE), also known as Wi-Fi Certified Enhanced Open, is specifically designed to provide encryption for open (unauthenticated) networks. It uses a Diffie-Hellman key exchange during the association process to create a unique, individualized encryption key for each client session, protecting users from passive eavesdropping without requiring a password. This perfectly matches the coffee shop's requirements.

  4. Question 4Intermediate

    Vulnerabilities, Threats, and Attacks · Select and use penetration testing tools

    A security team is using Kali Linux to perform a penetration test on their corporate WLAN, which uses WPA2-Personal. They have captured the 4-way handshake. Which tool from the Aircrack-ng suite would they use to attempt an offline dictionary attack against the captured handshake to recover the PSK?

    Show answer & explanation

    Correct answer: D

    The aircrack-ng tool itself is used for the actual cracking of keys. After capturing the 4-way handshake (typically using airodump-ng), the capture file is fed into aircrack-ng along with a wordlist (dictionary file). Aircrack-ng then iterates through the wordlist, attempting to find the correct PSK. Airmon-ng is used to put wireless cards into monitor mode, airodump-ng is for capturing packets, and aireplay-ng is for injecting packets (e.g., to perform a deauthentication attack to force a handshake).

  5. Question 5Advanced

    WLAN Security Design and Architecture · Implement or recommend appropriate wired security configurations to support the WLAN

    A large enterprise is designing a multi-tiered security architecture for its WLAN. The goal is to segment traffic from different user groups (Corporate, IoT, Guest) and apply different security policies to each. Which combination of wired-side security mechanisms is most effective for achieving this?

    graph TD subgraph WLAN AP1[AP] AP2[AP] end subgraph Wired Infrastructure SW[Access Switch] FW[Firewall] AAA[RADIUS Server] end subgraph Networks CorpNet[Corporate Network] IoTNet[IoT Network] GuestNet[Guest Network] end AP1 --> SW AP2 --> SW SW --> FW SW --- AAA FW --> CorpNet FW --> IoTNet FW --> GuestNet
    Show answer & explanation

    Correct answer: B

    This is the most robust and scalable solution. Using multiple SSIDs (e.g., 'Corp', 'IoT', 'Guest') allows for different authentication and encryption settings per group. Mapping each SSID to a separate VLAN segments the traffic at Layer 2. A RADIUS server can dynamically assign users/devices to the correct VLAN based on their credentials or attributes (Role-Based Access Control). Finally, a firewall with Access Control Lists (ACLs) is essential for enforcing security policies between the VLANs, such as preventing the Guest and IoT networks from accessing the Corporate network.

  6. Question 6Advanced

    WLAN Security Design and Architecture · Implement secure transitioning (roaming) solutions

    A university is implementing 802.11r Fast BSS Transition (FT) to improve roaming performance for students using real-time applications. The implementation uses 'FT over-the-Air'. What is the key difference in the roaming process when using FT over-the-Air compared to a standard WPA2-Enterprise roam?

    Show answer & explanation

    Correct answer: C

    The primary benefit of 802.11r FT is speed. In an 'FT over-the-Air' roam, the client exchanges the necessary security information (the 4-way handshake) with the new target AP as part of the initial management frame exchange (Authentication and Reassociation frames). This eliminates the need for a separate, time-consuming 802.1X/EAP re-authentication with the RADIUS server, drastically reducing roaming time from hundreds of milliseconds to under 50 milliseconds.

  7. Question 7IntermediateSelect 2

    Vulnerabilities, Threats, and Attacks · Implement network monitoring to identify attacks and potential vulnerabilities

    A security analyst receives an alert from the WIPS indicating a 'honeypot AP' has been detected. Which characteristics are indicative of this type of attack? (Select TWO)

    Show answer & explanation

    Correct answers: A, D

  8. Question 8Intermediate

    Security Lifecycle Management · Use effective change management procedures including documentation, approval, and notifications

    As part of a change management process, a network administrator is upgrading the firmware on all access points in the production environment. According to best practices for security lifecycle management, what is the most critical step to perform BEFORE deploying the firmware update to all APs?

    Show answer & explanation

    Correct answer: C

    While notifying users and backing up configurations are important parts of the change management process, the most critical step before a widespread production deployment is to validate the change. Testing the new firmware in a controlled lab environment or on a pilot group of APs allows the administrator to identify any potential bugs, performance issues, or security vulnerabilities introduced by the update without impacting the entire organization. This validation step is crucial for risk mitigation.

  9. Question 9Intermediate

    WLAN Security Design and Architecture · Understand the capabilities of EAP methods

    A security architect needs to choose an EAP method for a new corporate WLAN. The requirements are:

    1. Must use certificates for server validation.
    2. Must support user authentication via an existing Active Directory database.
    3. Must NOT require deploying certificates to all client devices.

    Which EAP method satisfies all these requirements?

    Show answer & explanation

    Correct answer: C

    Protected EAP (PEAP), typically used as PEAPv0/EAP-MSCHAPv2, meets all requirements. It uses a TLS tunnel, which requires a certificate on the authentication server for clients to validate. Inside this secure tunnel, it uses a second EAP method, usually MS-CHAPv2, which authenticates users against a directory like Active Directory using usernames and passwords. This avoids the administrative overhead of deploying certificates to every client device. EAP-TLS requires client-side certificates. EAP-MD5 is insecure and doesn't use certificates. EAP-FAST is Cisco-proprietary and uses PACs instead of certificates for the tunnel.

  10. Question 10Intermediate

    Security Policy · Write policies conforming to common practices

    A Chief Information Security Officer (CISO) is reviewing the WLAN security policy. The current policy states, 'Access Points must be physically secured.' The CISO finds this statement too vague. Which of the following is the BEST rewrite to make the policy statement specific, measurable, and enforceable?

    Show answer & explanation

    Correct answer: C

    This statement is the best rewrite because it is specific (defines locations and enclosure types), measurable (provides a height requirement), and enforceable (auditors can physically check for compliance). The other options are vague and use subjective terms like 'should', 'easily accessible', and 'strong measures', which are difficult to enforce or audit consistently.

Ready for the real thing?

The full CWSP-207 simulator has every exam-style question, timed mode, and instant scoring.