View Full CWNP CWNA-109 Exam Dumps and Practice Test Dumps
Question 321.
Which WLAN security approach is most appropriate when an organization requires per-user authentication, centralized access control, and the ability to revoke one user’s access without changing credentials for everyone else?
- 802.1X/EAP with centralized authentication
2. One shared WPA2-Personal passphrase
3. Open authentication
4. MAC address filtering only
Correct Answer: 1. 802.1X/EAP with centralized authentication
Explanation:
802.1X/EAP is designed for enterprise environments that need individualized user or device authentication. It commonly uses a RADIUS server to validate credentials or certificates and can integrate with centralized identity services. If one employee leaves the organization, that person’s credential can be disabled without changing access for everyone else. A shared personal-mode passphrase is simpler but provides weaker accountability and more difficult credential lifecycle management. Open authentication does not validate identity, while MAC filtering can be bypassed because MAC addresses are easily observed and spoofed. Enterprise WLAN security should also include proper server-certificate validation and appropriate EAP method selection.
Question 322.
In a typical 802.1X WLAN, which component requests network access and presents authentication credentials?
- Authentication server
2. Supplicant
3. Authenticator
4. DHCP server
Correct Answer: 2. Supplicant
Explanation:
The supplicant is the client-side component seeking authenticated access to the network. It may be built into the operating system, Wi-Fi client software, or a managed device configuration. The authenticator, usually the AP or WLAN infrastructure, controls access to the network and relays authentication messages. The authentication server, commonly RADIUS, evaluates the credentials or certificates. DHCP normally operates after network access has been established. Understanding these roles is important for troubleshooting because a failed connection may be caused by client configuration, WLAN infrastructure, certificate trust, RADIUS policy, or backend identity services.
Question 323.
Which device or service usually evaluates user credentials in an enterprise WLAN using 802.1X?
- Access point antenna
2. DHCP relay
3. RADIUS server
4. DNS resolver
Correct Answer: 3. RADIUS server
Explanation:
A RADIUS server commonly performs the authentication-server role in an enterprise 802.1X deployment. It receives authentication requests from the WLAN authenticator and evaluates credentials, certificates, or other identity information according to configured policy. The AP antenna is simply an RF component, while DHCP and DNS perform address-assignment and name-resolution functions. RADIUS logs are especially valuable during troubleshooting because they can reveal why an authentication attempt was accepted or rejected. WLAN professionals should correlate RADIUS events with wireless packet captures and timestamps when diagnosing enterprise authentication failures.
Question 324.
Which security practice is most important for protecting users against an evil twin that presents a fraudulent authentication server certificate?
- Hide the SSID
2. Use a shorter username
3. Disable PMF
4. Validate the authentication server certificate and trusted CA**
Correct Answer: 4. Validate the authentication server certificate and trusted CA
Explanation:
Proper server-certificate validation helps clients distinguish legitimate enterprise authentication infrastructure from a fraudulent server operated by an attacker. Clients should trust only approved certificate authorities and, where applicable, validate expected server identities. If certificate checks are disabled, users may unknowingly submit credentials to an evil twin. Hiding an SSID does not provide meaningful protection against WLAN impersonation, and PMF addresses a different security problem involving selected management frames. Certificate validation should ideally be enforced through centralized device management so users are not asked to make trust decisions manually during connection attempts.
Question 325.
Which feature helps protect selected deauthentication and disassociation management frames from spoofing?
- Protected Management Frames
2. WMM
3. DFS
4. OFDMA
Correct Answer: 1. Protected Management Frames
Explanation:
Protected Management Frames, or PMF, add cryptographic protection to selected robust management frames. This helps defend against attacks in which an adversary forges deauthentication or disassociation frames to disrupt client connectivity. WMM provides QoS prioritization, DFS protects radar systems, and OFDMA improves multi-user efficiency. PMF does not protect every wireless management frame, but it significantly improves security for critical management exchanges. Modern WLAN security designs increasingly depend on PMF, and it is required in certain newer Wi-Fi security modes. Client compatibility should be verified before enforcing it in environments containing legacy devices.
Question 326.
Which WLAN security technology should be considered obsolete because of serious cryptographic weaknesses?
- WPA3
2. WEP
3. WPA2-Enterprise
4. 802.1X/EAP
Correct Answer: 2. WEP
Explanation:
WEP is obsolete because its cryptographic design contains fundamental weaknesses that make it vulnerable to practical attacks. Attackers can recover WEP keys and decrypt traffic using well-known methods. WPA and WPA2 were introduced to address these weaknesses, and newer WPA3 mechanisms provide further improvements. 802.1X/EAP remains a valid enterprise authentication framework. Legacy hardware that requires WEP should generally be replaced or isolated rather than allowing weak security to persist on a modern enterprise WLAN. Security compatibility should never come at the expense of exposing an entire wireless network to known attacks.
Question 327.
Which encryption and integrity mechanism is most closely associated with WPA2’s stronger security compared with legacy WEP?
- TKIP only
2. RC4 only
3. AES-based CCMP
4. No encryption
Correct Answer: 3. AES-based CCMP
Explanation:
WPA2 standardized stronger protection using AES-based CCMP, which represented a major improvement over WEP and transitional TKIP-based security. CCMP provides both confidentiality and integrity protections designed for modern WLAN operation. WEP relied on weak RC4-based mechanisms and should no longer be used. TKIP was introduced as an interim measure during the transition away from WEP but is also considered obsolete for modern networks. WLAN professionals should understand the historical progression of security technologies because compatibility with old clients can sometimes tempt organizations to enable insecure legacy options.
Question 328.
Which security risk is most directly associated with using one pre-shared key for hundreds of employees?
- It automatically increases channel utilization
2. It disables roaming
3. It prevents MIMO
4. Revoking one user’s access may require changing the shared key for everyone**
Correct Answer: 4. Revoking one user’s access may require changing the shared key for everyone
Explanation:
A shared pre-shared key is easy to deploy but difficult to manage securely at large scale. If the credential becomes known to an unauthorized person or one employee leaves, administrators may need to change the key for every user and device. This creates operational overhead and weakens accountability because many people share the same credential. Enterprise authentication using 802.1X/EAP provides individualized credentials and more granular revocation. A PSK does not inherently disable roaming or MIMO, and it does not directly determine channel utilization. The main concern is identity, accountability, and credential lifecycle management.
Question 329.
Which WLAN security problem describes an unauthorized access point configured to imitate a legitimate SSID in order to attract clients?
- Evil twin
2. Hidden node
3. Co-channel contention
4. Adjacent-channel interference
Correct Answer: 1. Evil twin
Explanation:
An evil twin is a malicious or unauthorized access point configured to look like a legitimate WLAN, often by advertising the same or a similar SSID. Users may connect to it and expose credentials or traffic if proper authentication and certificate validation are not enforced. Hidden nodes and channel interference are RF performance problems rather than impersonation attacks. Because SSID names are easily copied, users should not rely on the network name alone to determine legitimacy. Strong enterprise authentication, server-certificate validation, PMF, and wireless monitoring all help reduce the risk posed by rogue or evil-twin infrastructure.
Question 330.
Which statement best describes the purpose of a wireless intrusion detection or prevention system in an enterprise WLAN?
- It assigns DHCP addresses
2. It can monitor the RF environment for rogue devices and suspicious wireless activity
3. It replaces all authentication mechanisms
4. It increases antenna gain
Correct Answer: 2. It can monitor the RF environment for rogue devices and suspicious wireless activity
Explanation:
Wireless intrusion detection or prevention capabilities monitor the radio environment for suspicious behavior such as rogue access points, unauthorized WLANs, unusual attacks, or policy violations. These systems can help administrators identify devices that do not belong to the managed infrastructure. They do not replace authentication, encryption, or access-control mechanisms and do not affect antenna gain. Effective wireless security is layered: strong authentication and encryption protect connections, PMF protects selected management frames, and monitoring helps detect unauthorized or abnormal wireless activity. Proper investigation is still required before classifying every unknown AP as malicious because neighboring legitimate networks may also be visible.
Question 331.
Which WLAN design document should describe expected client types, application needs, coverage targets, capacity, security, and roaming requirements before AP placement begins?
- Requirements document
2. ARP table
3. DHCP scope
4. RADIUS accounting log
Correct Answer: 1. Requirements document
Explanation:
A requirements document defines what the WLAN must accomplish before design decisions such as AP placement, channel width, or antenna selection are made. Requirements may include supported devices, application types, user density, target RSSI and SNR, roaming behavior, security, throughput, availability, and regulatory constraints. ARP tables, DHCP scopes, and RADIUS logs are operational data sources rather than design requirements. Starting with clearly defined requirements prevents the common mistake of deploying APs based only on coverage assumptions. It also creates measurable criteria against which the final WLAN can be validated after installation.
Question 332.
Which WLAN design mistake is most likely when AP placement is based only on signal coverage and ignores expected user density?
- Excessive certificate validation
2. Insufficient capacity
3. Too much antenna polarization
4. Too many RADIUS servers
Correct Answer: 2. Insufficient capacity
Explanation:
A coverage-only design can provide strong signal everywhere while still failing during busy periods because there may not be enough airtime or channel reuse for the number of active clients. Capacity planning considers user density, application demand, channel width, data rates, channel utilization, and how many independent channels are available. Strong RSSI alone does not provide additional airtime. This problem is common in lecture halls, cafeterias, conference areas, and other high-density spaces. WLAN design should therefore balance coverage and capacity rather than assuming one automatically guarantees the other.
Question 333.
Which characteristic should be considered when designing a WLAN for barcode scanners that have weaker radios than typical laptops?
- Only AP maximum PHY rate
2. Only switch port speed
3. Actual client transmit power and receive sensitivity
4. Only controller license count
Correct Answer: 3. Actual client transmit power and receive sensitivity
Explanation:
Client capabilities can significantly affect WLAN design. Barcode scanners may have lower transmit power, less capable antennas, fewer spatial streams, or different roaming algorithms than laptops. If AP power and coverage are designed only around high-performance survey adapters or laptops, production scanners may experience poor uplink connectivity or delayed roaming. Designers should therefore understand client transmit power, receive sensitivity, supported bands, supported data rates, and application behavior. The WLAN should be validated using representative production devices, especially when those devices are critical to warehouse or healthcare operations.
Question 334.
Which survey type provides the best evidence that a WLAN design works with real production clients after installation?
- Predictive survey only
2. Desktop floor-plan review
3. Inventory audit
4. Post-deployment validation survey**
Correct Answer: 4. Post-deployment validation survey
Explanation:
A post-deployment validation survey tests the actual installed WLAN against the requirements defined during design. It can include RSSI, SNR, channel utilization, channel reuse, roaming, retries, throughput, interference, and application performance. Testing should use representative client devices when their behavior matters. Predictive modeling is useful before installation but cannot perfectly reproduce real building materials, interference, mounting differences, or endpoint behavior. Inventory reviews confirm equipment presence but do not prove performance. Validation is therefore the strongest method for demonstrating that the deployed WLAN actually meets operational requirements.
Question 335.
Which survey method is performed before installation by placing a temporary AP at proposed mounting locations and measuring actual RF propagation?
- AP-on-a-stick survey
2. Passive inventory survey
3. RADIUS survey
4. VLAN survey
Correct Answer: 1. AP-on-a-stick survey
Explanation:
An AP-on-a-stick survey uses a temporary AP positioned at or near a proposed installation location and configured to approximate the final deployment. Measurements are then taken throughout the target area to evaluate actual propagation, wall attenuation, antenna behavior, and coverage. This approach is particularly valuable in warehouses, healthcare facilities, industrial sites, or buildings with unusual materials where predictive models may be uncertain. The survey should use representative antenna type, mounting height, orientation, and transmit power so the measurements reflect the final design as accurately as practical.
Question 336.
Which survey method uses software modeling and floor plans to estimate WLAN coverage before hardware is installed?
- Validation survey
2. Predictive survey
3. Spectrum survey only
4. Protocol-capture survey
Correct Answer: 2. Predictive survey
Explanation:
A predictive survey uses software to model expected RF propagation based on floor plans, wall types, attenuation assumptions, AP models, antenna patterns, transmit power, and other design inputs. It is efficient for creating an initial WLAN design and evaluating different AP placements. However, the accuracy of the result depends on the accuracy of the assumptions. Actual building materials, furniture, interference, and installation conditions can differ from the model. For this reason, predictive design should generally be followed by post-deployment validation, and challenging environments may also benefit from AP-on-a-stick measurements before installation.
Question 337.
Which troubleshooting tool is best suited to identifying a non-Wi-Fi interferer that produces RF energy but cannot be decoded as an 802.11 frame?
- DHCP server
2. RADIUS log
3. Spectrum analyzer
4. ARP cache
Correct Answer: 3. Spectrum analyzer
Explanation:
A spectrum analyzer displays RF energy across frequencies without requiring the signal to be valid 802.11 traffic. This makes it ideal for detecting sources such as microwave ovens, analog transmitters, industrial equipment, wireless cameras, or other non-Wi-Fi devices. A wireless protocol analyzer may reveal increased retries or corrupted traffic but cannot necessarily identify the non-802.11 waveform itself. DHCP, RADIUS, and ARP information operate at higher layers. Spectrum analysis is therefore an essential tool when symptoms suggest physical-layer interference that normal Wi-Fi frame analysis cannot explain.
Question 338.
Which troubleshooting tool is best for examining Association Requests, Authentication frames, retries, and reason codes?
- Cable certifier
2. Spectrum analyzer only
3. DHCP lease viewer
4. Wireless protocol analyzer**
Correct Answer: 4. Wireless protocol analyzer
Explanation:
A wireless protocol analyzer captures and decodes 802.11 frames, making it ideal for examining management exchanges, retries, reason codes, status codes, and authentication behavior. It can show exactly where the connection process succeeds or fails. A spectrum analyzer is complementary because it reveals RF energy and interference but does not decode the contents of Wi-Fi frames. DHCP lease information is useful only after sufficient network connectivity exists, while a cable certifier tests wired media. Protocol captures are especially valuable when correlated with infrastructure and RADIUS logs during complex connection or roaming problems.
Question 339.
Which troubleshooting practice should generally occur before making major WLAN configuration changes?
- Clearly define and reproduce the problem while collecting evidence
2. Increase all APs to maximum power
3. Disable security
4. Replace all APs
Correct Answer: 1. Clearly define and reproduce the problem while collecting evidence
Explanation:
Effective troubleshooting begins with a precise problem definition. Administrators should determine who is affected, where and when the issue occurs, which devices and applications are involved, and whether the problem can be reproduced. Relevant evidence may include RSSI, SNR, channel utilization, retries, packet captures, RADIUS logs, spectrum measurements, and wired-network statistics. Making large configuration changes before understanding the problem can mask the root cause or create new issues. A structured, evidence-based approach is faster and safer than randomly increasing power, replacing hardware, or weakening security.
Question 340.
A client associates successfully and receives an IP address, but cannot resolve website names while direct IP connectivity works. Which layer or service should be investigated first?
- 802.11 association
2. RF coverage
3. Antenna polarization
4. DNS**
Correct Answer: 4. DNS
Explanation:
If the client has successfully associated, authenticated, obtained an IP address, and can reach destinations directly by IP address, then basic RF connectivity and IP routing are already working. Failure to resolve website names points toward DNS configuration or reachability. Troubleshooting should therefore examine the client’s configured DNS servers, name-resolution queries, response behavior, and network path to the DNS service. Reinvestigating association or antenna polarization would not be the most efficient first step. A layered troubleshooting process helps administrators focus on the earliest point in the protocol stack where the observed behavior actually fails.