
CWAP-405 Certification - The Ultimate Guide [Updated 2026]
CWAP-405 Practice Exam and Study Guides - Verified By ActualCollection
NEW QUESTION # 11
When performing protocol analysis, you notice a high number of RTS/CTS frames being transmitted on an HT network. You suspect this may be due to HT protection mechanisms. Where in the Beacon frame would you look to determine which one of the four HT protection modes the AP is operating in?
- A. Non-HT Present Element
- B. HT Information Element
- C. HT Protection Element
- D. HT Operation Element
Answer: B
Explanation:
When performing protocol analysis, you would look at the HT Information Element in the Beacon frame to determine which one of the four HT protection modes the AP is operating in. The HT Information Element contains various subfields that provide information about the HT network configuration and operation. One of these subfields is the HT Protection field, which indicates whether any protection mechanisms are required for mixed-mode operation with non-HT STAs. The four possible values for this field are:
* No Protection: No protection mechanisms are required.
* Non-member Protection: RTS/CTS or CTS-to-self protection is required for all HT transmissions.
* 20 MHz Protection: RTS/CTS or CTS-to-self protection is required for all HT transmissions using a 40 MHz channel.
* Non-HT Mixed Mode: All HT transmissions must use a non-HT preamble and header . References:
CWAP-405Certified Wireless Analysis Professional Study and Reference Guide, Chapter 11: 802.11n
/ac/ax PHYsical Layer Frame Exchanges, page 378; CWAP-405Certified Wireless Analysis Professional Study and Reference Guide, Chapter 11: 802.11n/ac/ax PHYsical Layer Frame Exchanges, page 379.
NEW QUESTION # 12
Which piece of information is not transmitted in an HT PPDU header?
- A. PPDU length
- B. Channel number
- C. MCS index
- D. Number of Spatial Streams
Answer: B
Explanation:
The channel number is not transmitted in an HT PPDU header. An HT PPDU header is a part of the PPDU that contains information such as modulation, coding, data rate, and number of spatial streams for an 802.11n transmission. The channel number is not included in the HT PPDU header, as it is determined by the frequency band and channel width that are used by the transmitter and receiver. The channel number can be inferred from the frequency band and channel width, which are indicated by bits in different fields of the HT PPDU header, such as HT-SIG and HT-LTF. The other options are not correct, as they are transmitted in an HT PPDU header. The number of spatial streams, PPDU length, and MCS index are indicated by bits in the HT-SIG field of the HT PPDU header. References: [Wireless Analysis Professional Study Guide CWAP-
405], Chapter 4: 802.11 Physical Layer, page 108-109
NEW QUESTION # 13
You are attempting to work through a user complaint with the CWNP-recommended troubleshooting methodology.
What must be clearly identified in order to reduce the number of possible causes at step three?
- A. The device type
- B. The user name
- C. The user's IP configuration
- D. The problem
Answer: D
NEW QUESTION # 14
When configuring a long-term, forensic packet capture and saving all packets to disk which of the following is not a consideration?
- A. Total capture storage space
- B. Individual trace file size
- C. Real-time packet decodes
- D. Analyzer location
Answer: C
Explanation:
Real-time packet decodes are not a consideration when configuring a long-term, forensic packet capture and saving all packets to disk. Real-time packet decodes are useful for live analysis and troubleshooting, but they consume CPU and memory resources that could affect the performance of the capture process. For a long- term, forensic packet capture, it is more important to consider the analyzer location, the total capture storage space, and the individual trace file size. These factors affect the quality and quantity of the captured packets and the ease of post-capture analysis34 References:
* CWAP-405Study Guide, Chapter 2: Protocol Analysis, page 49
* CWAP-405Objectives, Section 2.1: Configure protocol analyzers
NEW QUESTION # 15
What action is taken automatically by 802.11 APs and client STAs as the signal strength of the link weakens in order to improve the quality of the RF communications overall?
- A. RSSI is increased
- B. Antenna gain is increased
- C. Output power is increased
- D. Data rates are reduced
Answer: D
NEW QUESTION # 16
You are troubleshooting throughput problems for a WLAN cell. The cell is provisioned with an 802.11ac dual- band AP. Users connected with both 5 GHz and 2.4 GHz connections are reporting performance problems.
The AP settings are properly optimized. No interface issues have been detected (either co-channel interference or non-Wi-Fi interference) and the number of associated users is low.
What should you analyze to resolve the issue?
- A. the Ethernet uplink and the network infrastructure
- B. The 5 GHz radio configuration
- C. The 2.4 GHz radio configuration
- D. The antennas used on the client devices
Answer: A
NEW QUESTION # 17
You have received reports of performance problems in a BSS. One specific user is indicating that her downloads are taking a very long time compared to other users around her. You want to determine if the AP is sending frames multiple times to get through to the user's computer.
Where should you monitor with the protocol analyzer to see retries from the AP in this scenario?
- A. Directly in the middle of the AP and client STA
- B. Capture from another AP in another BSS
- C. Very near the client STA
- D. Very near the AP
Answer: D
NEW QUESTION # 18
What is the default 802.11 authentication method for a STA when using Pre-RSNA?
- A. Shared Key
- B. PSK
- C. 4-Way Handshake
- D. Open System
Answer: D
Explanation:
The default 802.11 authentication method for a STA when using Pre-RSNA is Open System. This is the simplest and most common authentication method, which does not provide any security or encryption. In Open System authentication, the STA sends an Authentication Request frame to the AP, and the AP responds with an Authentication Response frame with a status code of success. After this, the STA can proceed to association with the AP . References: CWAP-405Certified Wireless Analysis Professional Study and Reference Guide, Chapter 6: MAC Sublayer Frame Exchanges, page 181; CWAP-405Certified Wireless Analysis Professional Study and Reference Guide, Chapter 6: MAC Sublayer Frame Exchanges, page 183.
NEW QUESTION # 19
As the WLAN engineer in your organization, you must troubleshoot performance problems related to co- channel interference (CCI).
What is a good measurement of CCI impact in addition to the number of APs seen on a channel?
- A. The frequency used
- B. Retries
- C. Non-Wi-Fi device count
- D. Utilization
Answer: A
NEW QUESTION # 20
In a Spectrum Analyzer the Swept Spectrogram plot displays what information?
- A. Reductions in frame transmissions
- B. Wi-Fi Device information
- C. The RF time domain
- D. RF power present at a particular frequency over the course of time
Answer: D
Explanation:
The Swept Spectrogram plot is a spectrum analysis plot that shows the RF power present at a particular frequency over the course of time. It can help identify trends and patterns in the RF spectrum over a longer period of time. It can also show how the RF environment changes over time and how different sources of RF signals affect each other. The other options are not correct, as they describe different types of plots or information that are not related to the Swept Spectrogram plot. References: [Wireless Analysis Professional Study Guide], Chapter 3: Spectrum Analysis, page 72-73
NEW QUESTION # 21
Given: Protocol analyzer often have useful graphical dashboards providing information about the health and operations of the WLAN.
What is a valid use of a graph showing the Top APs Based on Active Associations?
- A. Ensuring compliance with corporate security policies
- B. Locating overloaded APs
- C. Discovering the total number of client STAs on your network
- D. Evaluating the capacity handling on a specific channel
Answer: B
NEW QUESTION # 22
While troubleshooting DHCP issues, you perform a protocol capture in order to determine if the DNCP pool is depleted. The capture does not show DHCPnak messages.
Where else could you look to determine if the pool is depleted?
- A. DHCP server logs
- B. Spectrum analyzer
- C. AP logs
- D. Switch logs
Answer: A
Explanation:
A very common problem for WLANs is DHCP pool depletion. This occurs because many wireless clients come-and-go from the network quickly. If a client connects for only two or three minutes and the lease duration is set to multiple days (3-8 days is not uncommon), the IP address will be lost for that entire time. To resolve such issues, create more pools and reduce the lease duration to hours instead of days. Look for DHCP negative acknowledgement or server log errors to determine if the IP pool is depleted.
NEW QUESTION # 23
How is the length of an AIFS calculated?
- A. SIFS * Slot Time + AIFSN
- B. SIFS + AIFS * Time Unit
- C. DIFS + SIFS + AIFSN
- D. AIFSN * Slot Time + SIFS
Answer: D
Explanation:
The length of an AIFS (Arbitration Interframe Space) is calculated by multiplying the AIFSN (Arbitration Interframe Space Number) by the Slot Time and adding the SIFS (Short Interframe Space). An AIFS is a variable interframe space introduced by 802.11e to help prioritize medium access for different Access Categories (ACs). An AC is a logical queue that corresponds to a QoS (Quality of Service) level for different types of traffic. Each AC has a different AIFSN value, which determines how long it has to wait before attempting to access the medium. A lower AIFSN value means a higher priority and a shorter waiting time.
The Slot Time is a fixed value that depends on the PHY type and channel width. The SIFS is the shortest interframe space that is used for high-priority transmissions, such as ACKs or CTSs. The formula for calculating the AIFS length is: AIFS = AIFSN * Slot Time + SIFS. References: [Wireless Analysis Professional Study Guide CWAP-405], Chapter 7: QoS Analysis, page 194-195
NEW QUESTION # 24
You are considering disabling the data rates of 1, 2, 5.5 and 11 in the 2.4 GHz band.
What advantage might this provide to the networks operating in this band?
- A. The range of the PHY preamble and header will be reduced
- B. Frames that must be transmitted at the lowest common data rate can be transmitted at higher data rates after the change
- C. The RF signals will not travel as far
- D. The antennas will be able to zero in on the higher data rates better
Answer: B
NEW QUESTION # 25
The manager in the security group is concerned about compliance with security policies on the WLAN. The budget is not available for a full WIPS SOLUTION. He has asked you to implement a process that will verify compliance.
What would you recommend in such a scenario?
- A. Implement AP-based sensors throughout the facility and then monitor for performance issues with these sensors
- B. Use a laptop-based protocol analyzer that provides compliance reporting to monitor the environment on a periodic basis
- C. Simplify enable 802.11w, which will enforce management frame compliance
- D. Use the built-in spectrum analyzer features of the APs to ensure that WPA2-Enterprise is implemented throughout the organization
Answer: B
NEW QUESTION # 26
In what scenario is Open Authentication without encryption not allowed based on the 802.11 standard?
- A. When operating a BSS in FIPS mode
- B. When operating a BSS in a government facility
- C. When operating a BS5 in the CBRS band
- D. When operating a BSS in the 6 GHz band
Answer: D
Explanation:
Open Authentication without encryption is not allowed when operating a BSS in the 6 GHz band, according to the 802.11 standard. Open Authentication is a type of authentication method that does not require any credentials or security information from a STA (station) to join a BSS (Basic Service Set). Open Authentication can be used with or without encryption, depending on the configuration of the BSS and the STA. Encryption is a technique that scrambles the data frames using an algorithm and a key to prevent unauthorized access or eavesdropping. However, in the 6 GHz band, which is a newly available frequency band for WLANs, Open Authentication without encryption is prohibited by the 802.11 standard, as it poses security and interference risks for other users and services in the band. The 6 GHz band requires all WLANs to use WPA3-Personal or WPA3-Enterprise encryption methods, which are more secure and robust than previous encryption methods such as WPA2 or WEP. The other options are not correct, as they do not describe scenarios where Open Authentication without encryption is not allowed by the 802.11 standard.
When operating a BSS in the CBRS band, which is another newly available frequency band for WLANs, Open Authentication without encryption is allowed, but not recommended, as it also poses security and interference risks for other users and services in the band. When operating a BSS in FIPS mode, which is a mode that complies with the Federal Information Processing Standards for cryptographic security, Open Authentication without encryption is allowed, but not compliant, as it does not meet the FIPS requirements for encryption algorithms and keys. When operating a BSS in a government facility, Open Authentication without encryption is allowed, but not advisable, as it may violate the government policies or regulations for wireless security. References: [Wireless Analysis Professional Study Guide CWAP-405], Chapter 8: Security Analysis, page 220-221
NEW QUESTION # 27
Given a protocol analyzer can decrypt WPA2-PSK data packets providing the PSK and SSID are configured in the analyzer software. When performing packet capture (in a non-FT environment) which frames are required in order for PSK frame decryption to be possible?
- A. Reassociation
- B. Authentication
- C. Probe Response
- D. 4-Way Handshake
Answer: D
Explanation:
The 4-way handshake is the process that establishes the pairwise transient key (PTK) between the client and the AP in WPA2-PSK. The PTK is derived from the PSK, the SSID, and some random numbers exchanged in the handshake frames. The PTK is used to encrypt and decrypt the data frames between the client and the AP. Therefore, in order to decrypt WPA2-PSK data packets, a protocol analyzer needs to capture the 4-way handshake frames and have the PSK and SSID configured in the analyzer software12 References:
* CWAP-405Study Guide, Chapter 3: 802.11 MAC Layer Frame Formats and Technologies, page 87
* CWAP-405Objectives, Section 3.5: Analyze security exchanges
NEW QUESTION # 28
Recently, three rogue APs have been connected to the network and later discovered. You want to prevent future rogue AP installations as much as possible.
What is the first step to eliminating or reducing rogue APs on the network?
- A. Use IPSec between every AP and the network infrastructure
- B. Create a hash of the MAC addresses of all authorized devices and continually scan for non-matching hashes
- C. Define a direct policy that stipulates the ramifications of installing unauthorized devices
- D. Enable rogue detection in the existing authorized APs
Answer: D
NEW QUESTION # 29
What is used to respond with an uplink transmission to an MU-RTS trigger frame in the 802.11ax PHY?
- A. VHT PPDU
- B. HE SU PPDU
- C. HE TB PPDU
- D. HE MU PPDU
Answer: C
Explanation:
An HE TB PPDU (High Efficiency Trigger-Based Packet Data Unit) is used to respond with an uplink transmission to an MU-RTS trigger frame in the 802.11ax PHY (Physical Layer). An MU-RTS trigger frame is a frame that initiates a multi-user transmission opportunity (MU-TXOP) by requesting multiple stations (STAs) to send clear-to-send (CTS) frames on different spatial streams or resource units (RUs). An HE TB PPDU is a frame that contains data from multiple STAs that have been allocated RUs by an MU-RTS trigger frame or another type of trigger frame. An HE SU PPDU (High Efficiency Single User Packet Data Unit) is a frame that contains data from a single STA using all available spatial streams or RUs. An HE MU PPDU (High Efficiency Multi User Packet Data Unit) is a frame that contains data from multiple STAs using different spatial streams or RUs without being triggered by another frame. A VHT PPDU (Very High Throughput Packet Data Unit) is a frame that uses the 802.11ac PHY and does not support multi-user transmissions.
References:
CWAP-405Study Guide, Chapter 3: 802.11 MAC Layer Frame Formats and Technologies, page 101 CWAP-405Objectives, Section 3.4: Analyze multi-user transmissions CWAP-405Study Guide, Chapter 3: 802.11 MAC Layer Frame Formats and Technologies, page 99
NEW QUESTION # 30
How many frames make up the Group Key Handshake excluding any Ack frames that may be required?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
Explanation:
The Group Key Handshake consists of two frames excluding any Ack frames that may be required. The Group Key Handshake is used to distribute and update the Group Temporal Key (GTK) for encrypting broadcast and multicast traffic. The AP initiates the Group Key Handshake by sending a Group Key Message
1 frame to a STA, which contains the new GTK and other information. The STA responds with a Group Key Message 2 frame to the AP, which confirms the receipt of the GTK and other information. After this, both the AP and the STA can use the new GTK for encryption and decryption of broadcast and multicast traffic .
References: CWAP-405Certified Wireless Analysis Professional Study and Reference Guide, Chapter 7:
802.11 Security, page 246; CWAP-405Certified Wireless Analysis Professional Study and Reference Guide, Chapter 7: 802.11 Security, page 247.
NEW QUESTION # 31
Which one of the following statements is not true concerning DTIMs?
- A. DTIM stands for Delivery Traffic Indication Map
- B. Buffered Broadcast and Multicast traffic will be transmitted following a DTIM
- C. The DTIM interval can dictate when an STA will wake up to listen to beacon frames
- D. Every Beacon frame must contain a DTIM
Answer: D
Explanation:
Every Beacon frame must contain a DTIM is not a true statement concerning DTIMs. DTIM stands for Delivery Traffic Indication Message, and it is a subfield within the TIM (Traffic Indication Map) element in a Beacon frame. The DTIM indicates how many Beacon frames (including the current one) will appear before the next DTIM. For example, if the DTIM interval is set to 3, it means that every third Beacon frame will contain a DTIM. Buffered broadcast and multicast traffic will be transmitted following a DTIM, so that STAs in power save mode can wake up and receive them. The DTIM interval can also dictate when an STA will wake up to listen to Beacon frames, as some STAs may choose to only listen to Beacon frames that contain a DTIM . References: CWAP-405Certified Wireless Analysis Professional Study and Reference Guide, Chapter
6: MAC Sublayer Frame Exchanges, page 200; CWAP-405Certified Wireless Analysis Professional Study and Reference Guide, Chapter 6: MAC Sublayer Frame Exchanges, page 201.
NEW QUESTION # 32
......
Ultimate Guide to the CWAP-405 - Latest Edition Available Now: https://exams4sure.actualcollection.com/CWAP-405-exam-questions.html