OffSec Wireless Professional (OSWP) Practice Test
Gana confianza para OffSec Wireless Professional (OSWP). Practica los conceptos, comprende las respuestas y refuerza tus conocimientos pregunta a pregunta.
Probar una preguntaDescripción y detalles del examen
El examen OffSec Wireless Professional (OSWP) es una evaluación práctica y manual de habilidades de seguridad inalámbrica ofensiva. Evalúa la capacidad de un candidato para identificar, explotar y asegurar vulnerabilidades comunes en redes 802.11 (Wi-Fi). A diferencia de los exámenes teóricos, el OSWP requiere que realices ataques reales en un entorno de laboratorio controlado, demostrando competencia con herramientas como Aircrack-ng suite, Wireshark y hashcat para comprometer redes WEP, WPA y WPA2-PSK. El examen está diseñado para testers de penetración, consultores de seguridad, miembros de equipos rojos y administradores de red que buscan validar su capacidad para llevar a cabo evaluaciones profesionales de seguridad inalámbrica. Aprobar con éxito el OSWP significa que posees las habilidades prácticas y fundamentales necesarias para evaluar la postura de seguridad de la infraestructura inalámbrica, un componente crítico en las pruebas de penetración de redes modernas. Conecta la brecha entre la comprensión de los conceptos inalámbricos y su aplicación efectiva en escenarios del mundo real.
Preguntas de Muestra
Elige una respuesta y consulta la explicación para ver cómo funciona la práctica.
Coffee Shop Capture You are performing a wireless assessment at a public coffee shop. Using a monitor mode interface, you capture a large amount of 802.11 data traffic. You notice several data frames where the 'To DS' and 'From DS' flags in the Frame Control field are both set to 0.
What does this combination of flags (To DS=0, From DS=0) most specifically indicate about the captured frames?
Handshake Capture Analysis You have successfully captured a .cap file containing what appears to be a WPA2 4-way handshake from a target network. You plan to use aircrack-ng to test the handshake's validity and then attempt to crack the PSK using a wordlist.
Which of the following are REQUIRED steps to verify the handshake is valid and proceed with a dictionary attack? (Select TWO).
During a wireless penetration test, you are attempting to deauthenticate clients from a target WPA2-Personal network to capture the 4-way handshake. You have identified the BSSID and a connected client's MAC address. Which of the following aireplay-ng command syntaxes is correct for sending a directed deauthentication frame?
When preparing to perform a WPA3-SAE (Dragonfly) handshake capture for offline analysis, why is the traditional deauthentication attack used against WPA2 less reliably effective?
Coffee Shop Audit You are conducting a wireless security assessment for a small coffee shop. The owner uses a single consumer-grade wireless router for both the private 'Staff' network and the public 'Customer' network. The router's configuration page shows that Client Isolation (also called AP Isolation) is enabled for the 'Customer' SSID, but not for the 'Staff' SSID. Both SSIDs are broadcast from the same physical access point.
Given this scenario, which of the following statements accurately describe the security implications? (Select all that apply).
Oportunidades profesionales y salario
Los rangos son cifras del mercado de EE. UU. salvo que se muestre un rango local.
Qué temas cubre este examen
01Wireless Network Security Foundations
Temas
- Understanding wireless standards and encryption vulnerabilities
- Capturing and interpreting wireless traffic
Objetivos de aprendizaje
- Understanding wireless standards and encryption vulnerabilities: Analyzing encryption vulnerabilities; Understanding wireless standards
- Capturing and interpreting wireless traffic: Capturing and interpreting wireless traffic; Using Wireshark to analyze wireless traffic
02Wireless Reconnaissance and Exploitation
Temas
- Wireless reconnaissance techniques
- Exploiting wireless vulnerabilities
Objetivos de aprendizaje
- Wireless reconnaissance techniques: Using Aircrack-ng for wireless security assessment; Utilizing mac80211 for wireless attacks
- Exploiting wireless vulnerabilities: Creating a rogue AP; Exploiting WPS vulnerabilities; Determining chipset and driver for a Wi-Fi adapter