A security analyst is investigating network monitoring alerts in a enterprise corporate office. Wireless packet captures and syslog entries show that client laptops are receiving spoofed 802.11 Deauthentication frames originating from a legitimate Access Point's BSSID. Immediately following disassociation, affected clients connect to a rogue access point broadcasting the corporate ESSID and prompting users for authentication via an insecure EAP-GTC protocol with an untrusted RADIUS server certificate. Which of the following statements correctly identify the attack mechanism and the most effective combination of technical controls to mitigate this threat? (Select TWO.)
- The observed activity indicates an Evil Twin attack leveraging management frame spoofing to perform credential harvesting via authentication downgrade.Cevap
- Enforcing IEEE 802.11w Protected Management Frames (PMF) on access points and configuring client 802.1X supplicants to strictly validate server certificates will mitigate the attack.Cevap
- CThe log signatures demonstrate an RF Jamming attack designed to degrade the physical signal-to-noise ratio across all 2.4 GHz channels.
- DDeploying inline network-layer access control lists (ACLs) on corporate switch trunks to drop unsolicited broadcast ARP replies will prevent client disconnections.
Cevap
The incident represents an Evil Twin attack combined with wireless deauthentication spoofing. The required mitigations are enforcing 802.11w Protected Management Frames (PMF) to encrypt management frames and configuring strict RADIUS server certificate validation on client supplicants.
The scenario describes a classic Evil Twin deployment facilitated by a wireless deauthentication attack. Attackers send spoofed 802.11 disassociation/deauthentication management frames using the real access point's BSSID to disconnect target clients. Once disconnected, client devices automatically reconnect to the strongest signal for their configured ESSID, attaching to the attacker's rogue access point. The rogue AP attempts to harvest credentials via EAP-GTC downgrade and a self-signed RADIUS certificate. To counter this, organizations must deploy IEEE 802.11w Protected Management Frames (PMF) to cryptographically authenticate management frames (preventing spoofed deauth packets) and enforce strict server certificate validation in the client 802.1X supplicant configuration so devices refuse connection to unverified RADIUS servers.
Adım Adım Çözüm
Anahtar Kavram
Wireless Attack Indicators (Evil Twin, Deauthentication) and Mitigations (802.11w PMF, RADIUS Certificate Validation)
Tahmini Süre:2m 0s