Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CWNP CWSP-207 Exam - Topic 3 Question 42 Discussion

Given: During 802.1X/LEAP authentication, the username is passed across the wireless medium in clear text.From a security perspective, why is this significant?
B) The username is an input to the LEAP challenge/response hash that is exploited, so the username must be known to conduct authentication cracking.
A) The username is needed for Personal Access Credential (PAC) and X.509 certificate validation.
C) 4-Way Handshake nonces are based on the username in WPA and WPA2 authentication.
D) The username can be looked up in a dictionary file that lists common username/password combinations.

CWNP CWSP-207 Exam - Topic 3 Question 42 Discussion

Actual exam question for CWNP's CWSP-207 exam
Question #: 42
Topic #: 3
[All CWSP-207 Questions]

Given: During 802.1X/LEAP authentication, the username is passed across the wireless medium in clear text.

From a security perspective, why is this significant?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Murray
3 days ago
I feel like D is also valid. Dictionary attacks are common.
upvoted 0 times
...
Breana
8 days ago
Agreed! Option B makes sense. Username is key for cracking.
upvoted 0 times
...
Ira
14 days ago
This is a big issue! Clear text means easy interception.
upvoted 0 times
...
Jovita
19 days ago
D is a concern too, dictionary attacks are no joke!
upvoted 0 times
...
Lyda
24 days ago
B is spot on, knowing the username is crucial for cracking.
upvoted 0 times
...
Lino
29 days ago
Wait, are we really still using LEAP? Seems outdated.
upvoted 0 times
...
Emiko
1 month ago
Totally agree, makes it way easier for attackers.
upvoted 0 times
...
Sue
1 month ago
That's a big security risk, usernames in clear text?
upvoted 0 times
...
Shaniqua
1 month ago
I’m not entirely clear on the specifics, but I feel like the 4-Way Handshake in WPA/WPA2 is more about keys than usernames, so I’m hesitant about option C.
upvoted 0 times
...
Harrison
2 months ago
I vaguely recall something about dictionary attacks, so option D might be relevant since common usernames can be easily exploited.
upvoted 0 times
...
Lemuel
2 months ago
I think option B makes sense because if the username is known, it could help in cracking the authentication process, similar to what we practiced in our labs.
upvoted 0 times
...
Dalene
2 months ago
I remember that usernames being sent in clear text can lead to credential theft, but I'm not sure how it specifically relates to LEAP.
upvoted 0 times
...

Save Cancel