Home > Security Tips > Network Security Tactics > Tutorial test: Implementing WLAN security countermeasures
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

Tutorial test: Implementing WLAN security countermeasures


Lisa Phifer
06.23.2003
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Test your knowledge of wireless LAN countermeasures with this series of multiple-choice questions. To learn more about implementing wireless LAN countermeasures, listen to the accompanying SearchSecurity.com on-demand tutorial webcast. For a refresher course on identifying WLAN threats, take our other tutorial test.

To take the test, jot down your answers on a piece of scrap paper, then check your answers here. No peeking!

1. Which of the following should be considered when developing a wireless security policy?
a) Business needs that prompted WLAN deployment
b) Threats inherent to WLAN usage
c) Value of business assets put at risk by WLAN access
d) All of the above

2. Which of the following is NOT a possible business consequence of wireless attack?
a) Increased cost and resource competition due to unauthorized WLAN use.
b) Downtime due to DoS attack launched from WLAN.
c) Loss of irreplaceable data on stolen PDA.
d) Legal liability due to wireless eavesdropping on confidential data.

3. Companies should create acceptable use policies (AUP) for hotspots if they…
a) Are a hotspot operator / public Internet access provider.
b) Want to ban traveler use of public hotspots.
c) Plan to provide employees with hotspot accounts.
d) All of the above.

4. Steps that effectively help to reduce the risk of war driving do NOT include…
a) Positioning APs so that most signal falls within your workspace.
b) Pulling down window shades and closing office doors.
c) Adjusting AP power output.
d) Adding after-market directional antennas to focus signal.

5. Using MAC address control lists to explicitly deny access to a list of unauthorized devices is a highly effective and scalable countermeasure.
a) True
b) False

6. Putting a firewall between your WLAN and your wired network CANNOT
a) Narrow permitted access.
b) Throttle network usage.
c) Prevent peer-to-peer attack on the WLAN.
d) Log traffic to and from the WLAN.

7. Entry-level APs can be harder to defend because they often lack more advanced security features found in enterprise-grade APs.
a) True
b) False

8. Which of the following measures does NOT harden a wireless device against wireless peer attack?
a) Turning on WEP.
b) Running antivirus software.
c) Disabling unused interfaces.
d) Enabling personal firewall features.

9. Service Set Identifiers (SSIDs) are shared secrets that should not be disclosed to anyone except for authorized WLAN users.
a) True
b) False

10. Which of the following is considered a best practices recommendation for configuring Shared Key Authentication in private networks?
a) Use values that identify the AP location so that stations can find it.
b) Use alphanumeric values that are easy to remember.
c) The more traffic on the WLAN, the more often you should update key values.
d) Avoid hexadecimal values – they are too hard to enter correctly.

11. Extensible Authentication Protocol methods that should be used with 802.1X port access control on your wireless LAN include…
a) EAP-MD5
b) EAP-TLS
c) LEAP
d) Any EAP method that supports your security policy.
e) All of the above.

12. Protected EAP is harder to deploy than LEAP because it requires a client-side certificate.
a) True
b) False

13. Which of the following provides privacy for data transmitted to and from individual stations, preventing peers from eavesdropping on each other?
a) WEP with static shared keys.
b) TKIP with per-session base keys.
c) IPsec VPN tunnels.
d) B and C, but not A.

14. Where do TKIP encryption keys come from?
a) They're derived from a base key delivered via 802.1X.
b) They're derived from a base key configured as a passphrase.
c) They're derived by mixing in the source station's MAC address.
d) All of the above.

15. WEP and IPSec both encrypt data, so there is never any point in using both.
a) True
b) False

16. SSL "captive portals" protect the confidentiality of user logins and passwords, but do not encrypt user data after authentication.
a) True
b) False

17. The IETF IP Security (IPSec) standard does NOT provide…
a) Packet Source Authentication
b) Interactive User Authentication
c) Data Confidentiality
d) Data Integrity


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Fun with Security
Do you speak geek: Respecting the letter of the law
Do you speak geek: All hail e-mail!
Summer security quiz: Are you ready to go on vacation?
Quiz: Compliance
Passwords: Do you speak Geek?
Festive Season: Do you speak Geek?
Learn IT: How spam affects e-mail marketing campaigns
Infosec Know IT All Trivia: Securing Web services
Infosec Know IT All Trivia: IPsec
Infosec Know IT All Trivia: Intrusion detection

Network Security Tactics
Using Nessus Attack Scripting Language (NASL) to find application vulnerabilities
Screencast: Recovering lost data with WinHex
How to build security into a virtualized server environment
How to install and configure Nessus
How to run a Nessus system scan
Nessus: Vulnerability scanning in the enterprise
Screencast: An introduction to the Open Source Security Testing Methodology Manual (OSSTMM)
Understanding multifactor authentication features in IAM suites
Network intrusion prevention systems: Should enterprises deploy now?
Webmail security: Best practices for data protection

Infrastructure and Network Security
What's your infosec IQ?
VPNs: IPsec vs. SSL
Sensitive student data cracked at U. of Georgia
Microsoft patches IE spoofing problem
Countdown begins for Mydoom DDoS attacks
IE update clears up spoofing issue
Geer slams Windows dominance, calls for government intervention
Microsoft to disable spoofing syntax in IE
Mydoom variant targets security features, Microsoft
IE flaw could fool users in illicit downloads

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts