An IT technician is auditing the wireless security of a small retail store's network. The store uses a SOHO wireless router configured with WPA2-Personal. During a security assessment, the technician discovers that an attacker parked outside could exploit a feature on the router to crack the network passphrase within a few hours by brute-forcing an eight-digit PIN, regardless of how long or complex the WPA2 passphrase is. Which of the following actions should the technician take to eliminate this vulnerability?
- Disable Wi-Fi Protected Setup (WPS) on the wireless router.Cevap
- BReconfigure the wireless encryption algorithm from AES to TKIP.
- CImplement WPA2-Enterprise authentication using an external RADIUS server.
- DDisable SSID broadcasting and enable static MAC address filtering.
Cevap
Disable Wi-Fi Protected Setup (WPS) on the wireless router.
Wi-Fi Protected Setup (WPS) contains a major protocol flaw that allows attackers to brute-force the router's 8-digit PIN in under 11,000 attempts. Once cracked, WPS reveals the underlying WPA2 pre-shared key regardless of passphrase complexity. Disabling WPS in the router settings completely removes this attack vector.
Adım Adım Çözüm
Anahtar Kavram
Disabling Wi-Fi Protected Setup (WPS) to mitigate PIN brute-force vulnerabilities
Tahmini Süre:1m 15s