CISEC ACTUAL EXAM TERMINAL
CERTIFICATION EVALUATION COMPLETE
QUESTIONS WITH FULL SOLUTION
ALREADY PASSED
⩥ Zigbee.
Answer: - 802.15.4
- Low cost cable replacement technology
- Close to 100M nodes in 2012
- Honeywell = HVAC systems
- Zigbee used for low power consumption and rely on long, multi-year
battery life
⩥ Zigbee Security.
Answer: - Accomodate security at MAC(2), Network (3) and
Application (7) Layers
- Relies on master keys set by mfg, installer or end-user - Generates link
keys to encrypt traffic
- Encryption Based on AES-CCM (128 bit block cipher)
- Security optional - AES may be too resource intensive for lightweight
devices (battery life vs security)
- KillerBee = python-based framework by Joshua Wright for Zigbee and
other 802.15.4 devices
,⩥ 802.11x WiFi (1997).
Answer: - 802.11b = 11 Mbps@2.4GHz
- 802.11a = 54 Mbps@ 5 GHz
- 802.11g = 22/54 Mbps @ 2.4 GHz
- 802.11n = 100+ Mbps @ 5 GHz
- Large data packets supported through fragmentation at Layer 2
⩥ 802.11i.
Answer: - Provides strong encryption, replay protection, integrity
protection
⩥ Extensible Authentication Protocol (EAP).
Answer: - Authentication support for wireless
- Different EAP types suitable for different environments -- considering
clients, directory type, hardware
⩥ WiFi - WEP Security Issues.
Answer: = wired equivalent privacy
- Based on pre-shared secret common to all stations in same wireless
network
- Spec never included rotation of shared secret
- Not easy to change shared secrets
,- Recover WEP key after collecting millions of packets
- Tools used: WEPCrack, AirSnort, dwepcrack (Written for Linux or
BSD systems)
- New fast tools: wnet/reinj, WEPWedgie (<1hour)
⩥ WiFi Protected Access (WPA) (2003).
Answer: - WiFi Alliance = interoperability testing for 802.11 h/w
vendors, consumers
- Uses TKIP (Temporal Key Integrity Protocol)
- WPA2 (Preferred) - Vast improvement over WEP, requires Access
Point and NIC replacement (AES-CCMP)
⩥ WiFi Networks - protecting.
Answer: - Migrate from WEP > WPA > WPA2
- Use Strong Authentication mechanism like PEAP (Protected Extensible
Authentication Protocol) or TTLS (Tunnelled Transport Layer Security)
- Mutual authentication to mitigate MITM and masquerading attacks
- Always require mutual authentication
- Audit network installations for consistency in deployment and config
- Delete default admin passwords, community strings, or HTTP-enabled
config pages
- Educate users on how to spot suspect activity on WiFi network
, ⩥ WiFi - Top Security Risks for All Wireless Protocols and Standards.
Answer: - Eavesdropping
- Masquerading
- DoS
- Rogue APs
⩥ Wireless Eavesdropping.
Answer: - Signal can be picked up for >300 feet
- Use antennas (Pringles chip can) -- extend from 600 feet to several
miles
⩥ Wireless Eavesdropping Mitigation.
Answer: - Use strong encryption and authentication in lowest layer of
protocol possible (at PHY/MAC if avail)
- Use TKIP for WPA - prefer to use WPA2 (AES)
- Encrypt at multiple layers - low and high
- Design wireless network with minimal coverage area
- Audit network with packet sniffer (Kismet, Wireshark)
⩥ Wireless Masquerading.
Answer: - Impersonate an authorized client or access point
- Uses "Evil Twin" attack
CERTIFICATION EVALUATION COMPLETE
QUESTIONS WITH FULL SOLUTION
ALREADY PASSED
⩥ Zigbee.
Answer: - 802.15.4
- Low cost cable replacement technology
- Close to 100M nodes in 2012
- Honeywell = HVAC systems
- Zigbee used for low power consumption and rely on long, multi-year
battery life
⩥ Zigbee Security.
Answer: - Accomodate security at MAC(2), Network (3) and
Application (7) Layers
- Relies on master keys set by mfg, installer or end-user - Generates link
keys to encrypt traffic
- Encryption Based on AES-CCM (128 bit block cipher)
- Security optional - AES may be too resource intensive for lightweight
devices (battery life vs security)
- KillerBee = python-based framework by Joshua Wright for Zigbee and
other 802.15.4 devices
,⩥ 802.11x WiFi (1997).
Answer: - 802.11b = 11 Mbps@2.4GHz
- 802.11a = 54 Mbps@ 5 GHz
- 802.11g = 22/54 Mbps @ 2.4 GHz
- 802.11n = 100+ Mbps @ 5 GHz
- Large data packets supported through fragmentation at Layer 2
⩥ 802.11i.
Answer: - Provides strong encryption, replay protection, integrity
protection
⩥ Extensible Authentication Protocol (EAP).
Answer: - Authentication support for wireless
- Different EAP types suitable for different environments -- considering
clients, directory type, hardware
⩥ WiFi - WEP Security Issues.
Answer: = wired equivalent privacy
- Based on pre-shared secret common to all stations in same wireless
network
- Spec never included rotation of shared secret
- Not easy to change shared secrets
,- Recover WEP key after collecting millions of packets
- Tools used: WEPCrack, AirSnort, dwepcrack (Written for Linux or
BSD systems)
- New fast tools: wnet/reinj, WEPWedgie (<1hour)
⩥ WiFi Protected Access (WPA) (2003).
Answer: - WiFi Alliance = interoperability testing for 802.11 h/w
vendors, consumers
- Uses TKIP (Temporal Key Integrity Protocol)
- WPA2 (Preferred) - Vast improvement over WEP, requires Access
Point and NIC replacement (AES-CCMP)
⩥ WiFi Networks - protecting.
Answer: - Migrate from WEP > WPA > WPA2
- Use Strong Authentication mechanism like PEAP (Protected Extensible
Authentication Protocol) or TTLS (Tunnelled Transport Layer Security)
- Mutual authentication to mitigate MITM and masquerading attacks
- Always require mutual authentication
- Audit network installations for consistency in deployment and config
- Delete default admin passwords, community strings, or HTTP-enabled
config pages
- Educate users on how to spot suspect activity on WiFi network
, ⩥ WiFi - Top Security Risks for All Wireless Protocols and Standards.
Answer: - Eavesdropping
- Masquerading
- DoS
- Rogue APs
⩥ Wireless Eavesdropping.
Answer: - Signal can be picked up for >300 feet
- Use antennas (Pringles chip can) -- extend from 600 feet to several
miles
⩥ Wireless Eavesdropping Mitigation.
Answer: - Use strong encryption and authentication in lowest layer of
protocol possible (at PHY/MAC if avail)
- Use TKIP for WPA - prefer to use WPA2 (AES)
- Encrypt at multiple layers - low and high
- Design wireless network with minimal coverage area
- Audit network with packet sniffer (Kismet, Wireshark)
⩥ Wireless Masquerading.
Answer: - Impersonate an authorized client or access point
- Uses "Evil Twin" attack