Get CWAP-404 Products Practice Material for CWAP-404 Exam Question Preparation
Most Reliable CWNP CWAP-404 Training Materials
NEW QUESTION # 104
What is the default 802.11 authentication method for a STA when using Pre-RSNA?
- A. PSK
- B. 4-Way Handshake
- C. Open System
- D. Shared Key
Answer: C
Explanation:
Explanation
The default 802.11 authentication method for a STA when using Pre-RSNA is Open System. This is the simplest and most common authentication method, which does not provide any security or encryption. In Open System authentication, the STA sends an Authentication Request frame to the AP, and the AP responds with an Authentication Response frame with a status code of success. After this, the STA can proceed to association with the AP . References: CWAP-404 Certified Wireless Analysis Professional Study and Reference Guide, Chapter 6: MAC Sublayer Frame Exchanges, page 181; CWAP-404 Certified Wireless Analysis Professional Study and Reference Guide, Chapter 6: MAC Sublayer Frame Exchanges, page 183.
NEW QUESTION # 105
A PHY Header is added to the PSDU at which sub-layer?
- A. LLC
- B. Network
- C. MAC
- D. PHY
Answer: D
Explanation:
A PHY header is added to the PSDU at the PHY layer. A PHY header is a part of the PPDU that contains information such as modulation, coding, and data rate. The PHY header is added by the PHY layer when it converts a PSDU to a PPDU for transmission, or removed by the PHY layer when it converts a PPDU to a PSDU for reception. The other layers do not add or remove a PHY header.
NEW QUESTION # 106
You require 802.11ac capture solution.
You want to capture using native operating system tools if possible.
What operating system has built-in ability to capture 802.11ac frames assuming it is running on the appropriate laptop hardware?
- A. Windows 8.1
- B. Mac OS X
- C. Windows 10
- D. Windows 7
Answer: B
NEW QUESTION # 107
You are concerned with management overhead in your WLAN. When evaluating the network, you note that each dual-band AP provides for 4 SSIDs in each band with three secure SSIDs and one Open System SSID. The network runs only 802.11ac APs and uses 20 MHz channels in 2.4 GHz and 400 MHz channels in 5 GHz.
What can you do to reduce the impact of beacon frames on CCI and channel utilization?
- A. Use only 40 MHz channels
- B. Use the same security across all SSIDs
- C. Disable SSID broadcasting
- D. Increase the beacon interval
Answer: C
NEW QUESTION # 108
802.11k Neighbor Requests and Neighbor Reports are sent in what type of Management Frames?
- A. Reassociation Request and Reassociation Response
- B. RRM
- C. Action
- D. Beacon
Answer: C
Explanation:
Explanation
802.11k Neighbor Requests and Neighbor Reports are sent in Action frames. An Action frame is a Management frame that is used to perform various operations or functions related to the operation or maintenance of a wireless network. An Action frame consists of a Category field that indicates the type of action being performed, and a variable-length Action Details field that contains specific information related to the action. For example, an Action frame with a Category field value of 5 indicates a Radio Measurement action, and the Action Details field may contain a Neighbor Request or a Neighbor Report subelement .
References: CWAP-404 CertifiedWireless Analysis Professional Study and Reference Guide, Chapter 6: MAC Sublayer Frame Exchanges, page 207; CWAP-404 Certified Wireless Analysis Professional Study and Reference Guide, Chapter 6: MAC Sublayer Frame Exchanges, page 208; CWAP-404 Certified Wireless Analysis Professional Study and Reference Guide, Chapter 12: 802.11k/v/r/u/w/ai Amendments, page 434.
NEW QUESTION # 109
Which one of the following statements is not true concerning DTIMs?
- A. DTIM stands for Delivery Traffic Indication Map
- B. The DTIM interval can dictate when an STA will wake up to listen to beacon frames
- C. Buffered Broadcast and Multicast traffic will be transmitted following a DTIM
- D. Every Beacon frame must contain a DTIM
Answer: D
Explanation:
Every Beacon frame must contain a DTIM is not a true statement concerning DTIMs. DTIM stands for Delivery Traffic Indication Message, and it is a subfield within the TIM (Traffic Indication Map) element in a Beacon frame. The DTIM indicates how many Beacon frames (including the current one) will appear before the next DTIM. For example, if the DTIM interval is set to 3, it means that every third Beacon frame will contain a DTIM. Buffered broadcast and multicast traffic will be transmitted following a DTIM, so that STAs in power save mode can wake up and receive them. The DTIM interval can also dictate when an STA will wake up to listen to Beacon frames, as some STAs may choose to only listen to Beacon frames that contain a DTIM.
NEW QUESTION # 110
How many frames are exchanged for 802.11 authentication in the 6 GHz band when WPA3-Enterprise is not used, and a passphrase is used instead?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
Explanation
Two frames are exchanged for 802.11 authentication in the 6 GHz band when WPA3-Enterprise is not used, and a passphrase is used instead. Authentication is a process that establishes an identity relationship between a STA (station) and an AP (access point) before joining a BSS (Basic Service Set). There are two types of authentication methods defined by 802.11: Open System Authentication and Shared Key Authentication. Open System Authentication does not require any credentials or security information from a STA to join a BSS, and it consists of two frames: an Authentication Request frame sent by the STA to the AP, and an Authentication Response frame sent by the AP to the STA. Shared Key Authentication requires a shared secret key from a STA to join a BSS, and it consists of four frames: two challenge-response frames in addition to the request-response frames. However, Shared Key Authentication uses WEP (Wired Equivalent Privacy) as its encryption algorithm, which is insecure and deprecated. In the 6 GHz band, which is a newly available frequency band for WLANs, Shared Key Authentication is prohibited by the 802.11 standard, as it poses security and interference risks for other users and services in the band. The 6 GHz band requires all WLANs to use WPA3-Personal or WPA3-Enterprise encryption methods, which are more secure and robust than previous encryption methods such as WPA2 or WEP. WPA3-Personal uses a passphrase to derive a PMK (Pairwise Master Key), while WPA3-Enterprise uses an authentication server to obtain a PMK. Both methods use SAE (Simultaneous Authentication of Equals) as their authentication protocol, which replaces PSK (Pre-Shared Key) or EAP (Extensible Authentication Protocol). SAE consists of two frames: an SAE Commit frame sent by both parties to exchange elliptic curve parameters and nonces, and an SAE Confirm frame sent by both parties to verify each other's identities and generate a PMK. Therefore, when WPA3-Enterprise is not used, and a passphrase is used instead in the 6 GHz band, only two frames are exchanged for 802.11 authentication:
an SAECommit frame and an SAE Confirm frame. References: [Wireless Analysis Professional Study Guide CWAP-404], Chapter 8: Security Analysis, page 220-221
NEW QUESTION # 111
What types of wireless systems are illustrated?
- A. A 2.4 GHz cordless phone on channel 14 and a wireless RFID reader
- B. A Bluetooth v2.0 file transfer and a 40 MHz HT AP on channels 11, 7 (primary, secondary)
- C. An 802.11 HR/DSSS system using channel 2 and a digital FHSS phone
- D. An ERP IEEE 802.11 system using channel 6 and Bluetooth v1.2 discovery
Answer: D
NEW QUESTION # 112
What is the difference between a Data frame and a QoS-Data frame?
- A. QoS Data frames include a QoS information element
- B. QoS Data frames include an 802.1Q VLAN tag
- C. QoS Data frames include a DSCP control field
- D. QoS Data frames include a QoS control field
Answer: D
Explanation:
The difference between a Data frame and a QoS-Data frame is that QoS Data frames include a QoS control field. A Data frame is a type of data frame that is used to carry user data or upper layer protocol data between STAs and APs. A QoS Data frame is a type of data frame that is used to carry user data or upper layer protocol data between STAs and APs that support QoS (Quality of Service) features. QoS features allow different types of traffic to be prioritized and handled differently according to their QoS requirements, such as delay, jitter, throughput, etc.
QoS Data frames include a QoS control field in their MAC header, which contains information such as traffic identifier (TID), queue size (TXOP), acknowledgment policy (ACK), etc., that are used for QoS purposes. The other options are not correct, as they do not describe the difference between Data and QoS Data frames.
QoS Data frames do not include a DSCP (Differentiated Services Code Point) control field, which is part of the IP header in the network layer, not the MAC header in the data link layer. QoS Data frames do not include a QoS information element (IE), which is part of some management frames that indicate QoS capabilities or parameters, not data frames. QoS Data frames do not include an
802.1Q VLAN tag, which is part of some Ethernet frames that indicate VLAN membership or priority, not wireless frames.
NEW QUESTION # 113
When performing protocol analysis, you notice a high number of RTS/CTS frames being transmitted on an HT network. You suspect this may be due to HT protection mechanisms.
Where in the Beacon frame would you look to determine which one of the four HT protection modes the AP is operating in?
- A. HT Information Element
- B. HT Operation Element
- C. Non-HT Present Element
- D. HT Protection Element
Answer: A
Explanation:
When performing protocol analysis, you would look at the HT Information Element in the Beacon frame to determine which one of the four HT protection modes the AP is operating in. The HT Information Element contains various subfields that provide information about the HT network configuration and operation. One of these subfields is the HT Protection field, which indicates whether any protection mechanisms are required for mixed-mode operation with non-HT STAs.
The four possible values for this field are:
No Protection: No protection mechanisms are required.
Non-member Protection: RTS/CTS or CTS-to-self protection is required for all HT transmissions.
20 MHz Protection: RTS/CTS or CTS-to-self protection is required for all HT transmissions using a 40 MHz channel.
Non-HT Mixed Mode: All HT transmissions must use a non-HT preamble and header.
NEW QUESTION # 114
What is encrypted within the fourth frame of the 4-Way Handshake?
- A. GMK
- B. GTK
- C. PTK
- D. PMK
Answer: B
Explanation:
The GTK (Group Temporal Key) is encrypted within the third message of the 4-Way Handshake.
The 4-Way Handshake is a process that establishes a secure connection between a STA (station) and an AP (access point) using WPA2 (Wi-Fi Protected Access 2), which is a security protocol that uses AES- CCMP (Advanced Encryption Standard-Counter Mode CBC-MAC Protocol) as its encryption algorithm. The 4-Way Handshake consists of four messages that are exchanged between the STA and the AP. The first message is sent by the AP to the STA, containing the ANonce (Authenticator Nonce), which is a random number generated by the AP.
The second message is sent by the STA to the AP, containing the SNonce (Supplicant Nonce), which is a random number generated by the STA, and the MIC (Message Integrity Code), which is a value that verifies the integrity of the message. The third message is sent by the AP to the STA, containing the GTK, which is a key that is used to encrypt and decrypt multicast and broadcast data frames, and the MIC. The GTK is encrypted with the KEK (Key Encryption Key), which is derived from the PTK (Pairwise Temporal Key). The PTK is a key that is used to encrypt and decrypt unicast data frames, and it is derived from the PMK (Pairwise Master Key), the ANonce, and the SNonce. The fourth message is sent by the STA to the AP, containing only the MIC, to confirm the completion of the 4-Way Handshake. The other options are not correct, as they are not encrypted within the third message of the 4-Way Handshake. The PMK is a key that is derived from a passphrase or obtained from an authentication server, and it is not transmitted in any message of the 4-Way Handshake. The PTK is a key that is derived from the PMK, the ANonce, and the SNonce, and it is not transmitted in any message of the 4-Way Handshake. The GMK (Group Master Key) is a key that is generated by the AP and used to derive the GTK, and it is not transmitted in any message of the 4-Way Handshake.
NEW QUESTION # 115
A new firmware has been released for the AP model you use in your WLAN.
You have more than 120 of these APs installed.
What is a good reason for applying a firmware update on an enterprise AP?
- A. Enable new security features and patch vulnerabilities
- B. Enable 4x4:4 spatial streams on a 3x3:3 AP
- C. Disable lower data rates
- D. Enable the short guard interval
Answer: A
NEW QUESTION # 116
Given the screenshot shown, Choose the statement that accurately describes what is being seen by this protocol analyzer.
- A. One access point is using the 802.11 round robin Beacon feature.
- B. Three access points are on the same channel in the same physical area.
- C. Three wireless stations are participating in an Ad Hoc WLAN.
- D. A Single Channel Architecture (SCA) WLAN solution has three WLAN profiles configured
Answer: C
NEW QUESTION # 117
The PLCP sublayer provides framing by adding a header to create what type of data unit?
- A. MSDU
- B. PSDU
- C. PPDU
- D. MPDU
Answer: C
Explanation:
The PHY layer provides framing by adding a header to create a PPDU. A PPDU (PHY Protocol Data Unit) is the data unit that is transmitted or received over the wireless medium by the PHY layer. A PPDU consists of a PSDU (PHY Service Data Unit) and a PHY header, which contains information such as modulation, coding, and data rate. The PHY layer adds the PHY header to the PSDU to create a PPDU for transmission, or removes the PHY header from the PPDU to extract the PSDU for reception. The other options are not correct, as they are not created by adding a header at the PHY layer. An MPDU (MAC Protocol Data Unit) is created by adding a MAC header and FCS to an MSDU (MAC Service Data Unit) at the MAC layer. An MSDU is the data unit that is passed from the LLC sublayer to the MAC sublayer or vice versa.
NEW QUESTION # 118
During an initial install of a controller-based WLAN, the APs are not locating the WLAN controller.
The controller is two router hops away from the nearest AP. DHCP is not used. When performing a packet trace, you see a DNS response code of 3 targeted at one of the APs.
What is the problem?
- A. The DNS server is not authoritative for the domain
- B. The authentication to the DNS server failed
- C. The controller host record has not been created in the DNS server
- D. The router is not forwarding packets to the DNS server
Answer: C
NEW QUESTION # 119
What is an AIFS?
- A. A medium access method introduced by 802.11n, but never implemented
- B. The shortest period of time a STA can sleep
- C. A variable Interframe Space introduced by 802.11e to help prioritize medium access for different Access Categories
- D. A form of aggregation performed at the PLCP sub-layer
Answer: C
Explanation:
An AIFS is a variable interframe space introduced by 802.11e to help prioritize medium access for different Access Categories (ACs). An interframe space is a period of time that a STA (station) has to wait before attempting to access the medium. An AIFS is a type of interframe space that varies depending on the AC of the traffic. An AC is a logical queue that corresponds to a QoS (Quality of Service) level for different types of traffic. There are four ACs defined by 802.11e:
AC_VO (Voice), AC_VI (Video), AC_BE (Best Effort), and AC_BK (Background). Each AC has a different AIFSN (Arbitration Interframe Space Number) value, which determines how long it has to wait before attempting to access the medium. A lower AIFSN value means a higher priority and a shorter waiting time. The other options are not correct, as they do not describe what an AIFS is.
An AIFS is not a medium access method introduced by 802.11n, but never implemented, as it is part of the 802.11e standard and widely used in QoS-enabled WLANs. An AIFS is not a form of aggregation performed at the PHY layer based on 802.11e UP values interpreted from DSCP values, as aggregation is a technique that combines multiple frames into one larger frame to improve efficiency and throughput, not prioritization or medium access. An AIFS is not the shortest period of time a STA can sleep, as sleeping is a power saving mode that allows a STA to conserve battery power by periodically turning off its radio, not accessing the medium.
NEW QUESTION # 120
Which parameters accurately describe the Beacon Interval field in the Beacon frame? (Choose 2)
- A. easured in time units of 1024 µs
- B. 4-octet length
- C. Indicates the desired time interval between TBTTs
- D. Value can range from 0 to 2007
- E. Indicates the exact time interval between Beacon transmissions
Answer: A,C
NEW QUESTION # 121
You are troubleshooting problems with DHCP in relation to lightweight APs. They vendor class identifier (VCI) is not specified in the DHCP server. When you contact vendor support, they inform you that it is not necessary.
When is this information true?
- A. When the DHCP server is directly connected to the subnet
- B. When only one client option 43 value is required
- C. When only one AP exists on the subnet
- D. When only one client option 60 value is required
Answer: B
NEW QUESTION # 122
Which one of the following is not an 802.11 Management frame?
- A. Authentication
- B. Action
- C. Beacon
- D. PS-Poll
Answer: D
Explanation:
A PS-Poll (Power Save Poll) frame is not an 802.11 management frame. A PS-Poll frame is a type of control frame that is used by a STA in power save mode to request data frames from an AP. A STA in power save mode can conserve battery power by periodically sleeping and waking up. When a STA sleeps, it cannot receive any data frames from the AP, so it informs the AP of its power save status by setting a bit in its MAC header. The AP then buffers any data frames destined for the sleeping STA until it wakes up. When a STA wakes up, it sends a PS-Poll frame to the AP, indicating its association ID and requesting any buffered data frames. The AP then responds with one or more data frames, followed by an ACK or BA frame from the STA. The other options are not correct, as they are types of 802.11 management frames. An Action frame is used to perform various management actions, such as spectrum management, QoS management, radio measurement, etc. A Beacon frame is used to advertise the presence and capabilities of an AP or BSS. An Authentication frame is used to establish or terminate an authentication relationship between a STA and an AP.
NEW QUESTION # 123
......
LATEST CWAP-404 Exam Practice Material: https://examcompass.topexamcollection.com/CWAP-404-vce-collection.html

