Your companys wireless network was recently compromised by a - CompTIA-N10-009

Question

Your company’s wireless network was recently compromised by an attacker who utilized a brute force attack against the network’s PIN (Personal Identification Number) to gain access. Once connected to the network, the attacker modified the DNS (Domain Name System) settings on the router and spread additional malware across the entire network.

Which TWO of the following configurations were most likely used to allow the attack to occur?

Answers
  1. correct
  2. correct
Explanation

Correct Answers:
A. WPS enabled
B. Default administrative login credentials

  1. A. WPS (Wi-Fi Protected Setup) enabled:

    • WPS allows users to connect to a wireless network using a PIN or a physical button. The PIN-based method is vulnerable to brute-force attacks due to its weak PIN mechanism (an 8-digit PIN is effectively two sets of 4-digit PINs, making it easy to crack).
    • In this scenario, the attacker exploited WPS to gain unauthorized access to the wireless network.
  2. B. Default administrative login credentials:

    • After accessing the network, the attacker modified the DNS settings on the router. This indicates that the attacker likely used default administrative login credentials (e.g., admin:admin or admin:password) to gain control of the router.
    • Default credentials are widely known and easily exploitable if not changed.

Why the Other Options Are Incorrect:

  • Router with outdated firmware:

    • While outdated firmware could introduce vulnerabilities, the scenario specifically points to a brute-force attack on WPS and the modification of router settings using default credentials. There is no indication that firmware vulnerabilities were exploited here.
  • WPA2 (Wi-Fi Protected Access version 2) encryption enabled:

    • WPA2 is a secure encryption standard when implemented properly (e.g., with a strong password). The issue in this case was not with WPA2 encryption but with the misuse of WPS, which bypasses the need for a strong WPA2 passphrase.
  • TKIP (Temporal Key Integrity Protocol) encryption protocols:

    • TKIP is an older encryption protocol and less secure than AES, but it is unrelated to the attack described. The attacker exploited WPS and weak router credentials, not encryption protocols.
  • Guest network enabled:

    • Guest networks are isolated by design and typically cannot access internal resources. The attack described targeted the main network via WPS and router admin credentials, not a guest network.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered