Overview
Join Jeff Kish for a review of this course! We'll use the end-of-skill quiz format to refresh our knowledge on the subjects covered.
Recommended Experience
- 1 to 2 years Archives
Related Job Functions
- Any
Jeff Kish has over 15 years of IT experience, focusing mainly on core infrastructure and data center technologies. He holds a number of Cisco certifications, including CCIEs in Routing and Switching and Data Center. He also focuses on network programmability and software-defined networking.
Intro
Let's review the major CWSP topics!
Review Quiz 1-5
Let's get started with our first set of questions.
Review Quiz 6-10
We're moving into the next batch of questions!
Review Quiz 11-15
We're halfway there, let's keep it going!
Review Quiz 16-22
We're in the home stretch, now! Finish strong!
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
Intro
0:00[AUDIO LOGO]
0:05Welcome to a review of the CWSP course.
0:08Here we are at the very end of this course.
0:10We've recovered a whole lot up until now.
0:13We think all the way back to when we first started.
0:15And we started a high level and took a look
0:16at the concept of security policies.
0:18We talked about the different regulatory policies
0:21that we have to worry about, especially as it relates
0:23to the payment card industry, and health care, and data,
0:27and with GDPR, and such.
0:28And then we got into a little bit more technical world.
0:31We had to talk about authentication methods,
0:33encryption methods, understanding
0:35the differences between WPA2 and WPA3,
0:38understanding TKIP versus CCMP and GCMP, and all
0:43these different methods.
0:45We had to worry about OWE and where that fits into things.
0:48And even in the last few skills here,
0:51we've been taking a look at all the different systems
0:53and approaching things a little bit more from a high level
0:56once again, looking at ways that we can lock down
0:58our wired network and make sure that we are deploying
1:01maybe a wireless IPS and what some of the value is there.
1:04And there's just a tremendous amount of information
1:06that we've covered.
1:07And so at the end of the skill or under the course,
1:10I always like to go back and say, let's
1:12just review via our quiz methodology
1:15to make sure that we remember some of the key points.
1:17Now, to be clear, we won't be able to cover
1:19every single facet of this course in 45 minutes.
1:22I can doubt that that expectation is there,
1:25but it's worth stating nonetheless.
1:27We want to make sure that we understand this material inside
1:29and out.
1:30So this is a great opportunity for us
1:32to hit the pause button here as we ask the questions
1:35and just say, OK, do I know the answer to this?
1:38Can I answer this?
1:39Every single quiz question that we have will
1:42have a reference at the bottom.
1:43Just like we do at the end of these skills,
1:45we always ask a series of quiz questions,
1:48and we reference the videos.
1:49In this case, we'll be referencing the skill.
1:51And so if you can't answer a quiz question,
1:53then it's a great opportunity to flag that skill to go back
1:57and say, OK, I need to review that skill
1:59and make sure that I've got all that information down.
2:01It might be as simple as reviewing your notes.
2:03It might require a little bit more
2:07of going back and rewatching some of those videos.
2:09But either way, again, what we're going to do
2:11is we're just going to go through--
2:13I believe we're at 22 questions--
2:16asking all of those and making sure
2:18that we understand each one of those, hit the pause button,
2:21make sure that you can answer it yourself
2:23before we answer the question to move on.
2:25So either way, let's dive into this review.
2:27I will see you in the next video.
Review Quiz 1-5
0:00[AUDIO LOGO]
0:05All right.
0:05Let's jump into this quiz.
0:07And you'll recognize that this format is
0:08going to mimic what we do at the end of the skill
0:11where we've got a question here, or we're not
0:12going to provide any silence, we're
0:13just going to ask the question and start to answer it.
0:16So again, use that pause button.
0:17Make sure that you are able to answer this question
0:20under your own power rather than just sitting there watching it.
0:22It's, again, a great opportunity to test your knowledge
0:25while also identifying areas of weaknesses,
0:27and making sure that we shore up all of those areas before we
0:30go and take the exam.
0:32So first question out of 22--
0:34what is a major factor as to why wireless networks increase
0:38the attack surface for an organization?
0:40So this is one of those high-level conversations
0:43that we had at the very start of the course.
0:45We talked about the concept of the attack surface.
0:47The attack surface is basically all of the ways
0:50that the bad actors can try to crack into our network.
0:54And so if we keep a very low attack surface,
0:56that means that maybe there's only a few ways
0:58that they could break in.
1:00But if we have a large attack surface,
1:01it really gives them a whole lot more options
1:03for how to actually attack our network.
1:06Now, wireless is a big deal from an attack surface perspective
1:10because of B here--
1:11the fact that our signals propagate beyond our walls.
1:14I no longer have to worry about just keeping my doors locked.
1:18If I didn't have to worry about wireless,
1:20the threat actors would actually have to break into the building
1:24potentially, maybe land in a conference room
1:26so that they could plug into the wall.
1:28Whereas now the wireless signals go outside of the building,
1:30and so they could just sit here in the parking lot
1:33inside of their car and they could
1:35be trying to attack the wireless,
1:36or otherwise passively eavesdropping if they have
1:39a way to decrypt the traffic.
1:41And so this is why our attack surface increases
1:43when we talk about wireless, and frankly, it's
1:46why we have an entire course about wireless security.
1:48And so let's go ahead and start with the fundamental principle
1:52that wireless security matters because if we don't secure
1:55our wireless, we're going to have situations like this,
1:58where threat actors will use the wireless to gain access
2:01to our internal network.
2:03Question two-- which type of hacker
2:04should be hired as part of a penetration test?
2:07So there's a couple of facets to this question
2:09that I wanted to address.
2:10First of all, let's remember what a penetration test is.
2:14This is a big factor when it comes to not only the CWP
2:17blueprint, but also just in terms of making sure
2:20that we have a secure environment.
2:22The idea is typically that I've built out my network, whatever
2:26is encompassed within this.
2:28We've got the wireless in here.
2:29We've got our firewalls.
2:31We've got our switches and our routers.
2:33And so we've built a security policy.
2:36We've wrapped all of these devices
2:37up in our security policy.
2:39And so in most cases, what we're going to do
2:41is we're going to hire somebody to come in and try
2:45to attack this secure network that I built out.
2:49And the idea here is that will help
2:51to identify the weak areas that maybe we didn't know existed--
2:55sort of like this quiz it's supposed to do,
2:57to identify the areas of weaknesses.
3:00And so if we're going to hire a hacker,
3:03this is the other part of the question, what type of hacker
3:05should we be hiring?
3:06Well, in every single case, we should absolutely
3:09be hiring white hat hackers.
3:10And if we're going through an organization--
3:13and this isn't a conversation about,
3:15oh, I've got the option to hire one of these over the other,
3:19if anytime I go to an organization,
3:21it's going to be white hat hackers because white hat
3:25hackers are ethical hackers.
3:27That's another phrase for these.
3:28These are people who have hacking skills,
3:30but they're not using it for nefarious purposes.
3:32They're not even using it for selfish or personal reasons
3:35other than to maybe make a dollar because they're
3:38hiring their services out and saying that, I will use
3:41my hacking skills to try to help you to increase your security
3:45defenses.
3:46Now, black hat hacker, these types
3:50are the ones who are doing hacking for nefarious purposes.
3:53They might be thinking that they're vigilantes
3:57and they're going to go out and obtain justice in some way,
4:00or maybe they're hacktivists as we call them.
4:03They're activists who are going to use their hacking
4:05skills in order to accomplish something,
4:07or maybe they're just crooks.
4:08Maybe they just want to break into a network
4:10and steal a bunch of information and make
4:12a bunch of money that way.
4:13Now, gray hat hackers sort of fall in between there.
4:16It's usually more so that they're
4:18just in it for themselves.
4:19They'll use their hacking skills for good purposes
4:22or bad purposes just depending on what it is that they
4:24want most in the moment.
4:26So let's make sure we understand the different types of hats,
4:29and this is how we refer to hackers.
4:31And again, a lot of it comes down
4:32to white hat hackers are ethical hackers, they can help us out,
4:36whereas black hat hackers, these are
4:39the ones who are using their skills for nefarious purposes.
4:43Next question-- what does a security information and event
4:46manager, or a SIEM, provide?
4:48So we talked about a lot of different tools
4:50throughout this course, and a SIEM is a very important one,
4:54it's going to primarily provide us with high fidelity alerting.
4:57The idea here is that we can have
4:59a bunch of systems that are all supposed
5:01to be detecting when there is maybe
5:03some sort of suspicious traffic flow.
5:06But the problem is we've got all of these traffic flows going
5:09through the network, and as we look
5:10at each one of these traffic flows,
5:12if there happens to be a suspicious one in here,
5:14yeah, that's great if we do pick up on it.
5:17But in the meantime, what if it thinks
5:18that this is a suspicious traffic
5:21flow, and this one and this one and this one and this one?
5:24And so we could use some help, maybe
5:27have a centralized system in here.
5:28And this is what the SIEM would be.
5:30And we're going to take all of this information
5:32from all these other systems, maybe their IPSs
5:35and the wireless IPS that we talked about,
5:37for example, maybe other firewalls and things like that.
5:42And so we're going to take all that information,
5:44and we're going to run analytics against it
5:46and we're going to try to make sure that we
5:48don't have false positives.
5:49That way, when we in IT do receive an alert
5:53that we know it's a good one because otherwise,
5:55if I was receiving all of these alerts
5:58down and every single day I'm just receiving
6:00more and more alerts and as far is I can tell all of them
6:03are perfectly fine, well, I'm eventually
6:06going to start ignoring those alerts
6:08so that when there is an actual suspicious traffic
6:11flow in here, I'm going to miss it.
6:13And so this is why high fidelity alerting is so important
6:16and why a SIEM can help us to really shore up
6:19our defenses in this regard.
6:20Question four-- match the following regulatory policies
6:23to one of these categories-- card payment, health care,
6:26and data protection?
6:27One of the biggest takeaways from the couple of skills where
6:30we focused on different regulatory practices
6:33is just understanding what each one of these is talking about.
6:36So when we look at A, for example,
6:37this is the payment card industry certification
6:40around data security.
6:41And so what we want to do is understand that,
6:44OK, so this regulatory practice, this compliance,
6:48set of compliance rules, this is around the card payment
6:51industry.
6:53GDPR, on the other hand, this is about data protection.
6:57This is that law that was passed in the EU,
7:00and it impacts everyone worldwide
7:03because if anybody is storing data
7:05that belongs to a resident in the EU,
7:07they must abide by GDPR.
7:09And so pretty much any corporation
7:12in the world doing business in Europe
7:13is going to have to give this a really close look.
7:16HITECH and HIPAA, these are in the US,
7:18and these are related to health care.
7:21And so again, we don't have to really know
7:23all of the details for performing a PCI audit per se,
7:27or a HIPAA audit, or GDPR, or any of these things,
7:30we don't have to drill into the details
7:31for this particular exam, but at a minimum at a high level,
7:35we should absolutely understand what
7:37the purpose of these rules of compliance are
7:39and what some examples are around things that maybe we're
7:42allowed to do and what we're not allowed
7:44to do with regards to storing the data for our users.
7:47All right.
7:47Question five, we've got a scenario
7:49here-- an organization determines that a single data
7:51breach would cost $2 million, and a breach is likely to occur
7:55once every three years.
7:57Would a $1 million a year solution
8:00be financially justified?
8:01Well, this type of scenario is going
8:03to come down to that equation that we had written out,
8:05which is the annual loss expectancy is
8:08equal to the single loss expectancy
8:10times the annual rate of occurrence.
8:13That might sound like a fancy algebra equation,
8:16but at the same time, it's pretty straightforward.
8:18It's basically saying the amount of money
8:20that I'm going to have to spend in a year is
8:23equal to the amount of money I'm going
8:25to have to spend for a breach times the number of times
8:28that breach occurs.
8:30So basically, what we're saying here
8:31is that I want to compare how much I expect
8:34to lose to how much the solution is actually costing me
8:37on an annual basis.
8:39So my SLE, my single loss expectancy here is $2 million.
8:43So let's plug that in.
8:44We've got $2 million for the SLE,
8:46and the annual rate of occurrence
8:48is once in three years.
8:49So this is actually multiplied by one-third, not by three.
8:52So make sure we get that number right.
8:54It's occurring once every three years, not three times a year.
8:57And so when we multiply that out, that comes out to 2/3
9:01of $1 million, and so that would be roughly $667,000.
9:06And so if we could lock down this data breach for $1 million
9:09a year, is it financially justified?
9:11In this case, the answer is actually no.
9:13Because we're going to spend $1 million a year and only
9:17save potentially 2/3 of $1 million.
9:20Now, there's all kinds of other conversations
9:22to have around this.
9:23For example, do we owe it to our customers
9:26to not allow data breaches if we're worried about this?
9:30We also understand that this once in three years
9:33is very much a guess in a lot of ways.
9:36But at the same time, this type of equation
9:38is what helps us to understand what level of a solution we
9:42should be deploying, because I might look at the $1 million
9:44a year solution and say that this takes it from once
9:47in three years to once in five years
9:49or something along those lines.
9:50It's never going to eliminate the possibility of a data
9:53breach.
9:53But if I could, for example, deploy something that's
9:57half a million a year, and this would take me
10:00from three years to four years, well, now we're
10:03talking something that makes a little bit more financial sense
10:05in this situation because we understand that half a million
10:09a year is less than the 2/3 and it's
10:11going to make it so that it happens even less often.
10:14And so we might have to use this type of method,
10:18and especially this equation in order
10:20to decide what type of solution to deploy that will end up
10:24helping me to avoid my data breaches
10:26and incidents in the future.
Review Quiz 6-10
0:00[AUDIO LOGO]
0:05Question number 6 what is the primary value of Black Box
0:08penetration tests?
0:10So we need to think back to talking about penetration
0:13testing and remember that there were
0:15these two different methodologies we discussed.
0:17We had White Box and Black box.
0:19The White Box methodology is when we actually hand
0:23documentation to the testers.
0:25Say, OK, here's all the information.
0:27Here's my firewall vendor.
0:29Here's my routing and switching vendor, my wireless vendor
0:31information.
0:32Here's a bunch of IP addresses, whatever
0:34I deem to be necessary for this penetration tester
0:37to really go at my network.
0:39Now the advantage to that is that they
0:41are going to be able to attack specific vulnerabilities
0:44for the information that I gave them
0:47or using the information I gave them.
0:48Maybe they know my firewall vendor
0:50has a particular vulnerability if I haven't fully
0:53patched my firewall or whatever the situation is.
0:56And so that is this White Box testing
0:59is going to give me more in-depth testing,
1:01I could argue because it's going to make sure that if there's
1:04any specific vulnerability that I may have missed
1:07that this company should hopefully
1:09be able to tell me that.
1:10Now the Black Box penetration test
1:12this is going to be a little bit more accurate testing.
1:15And what we mean by that when we think about it
1:18is that the Black Box test is not
1:21being given the documentation.
1:23The hackers that I'm hiring to try to break into my network,
1:26for example, I'm not telling them anything about it,
1:29which actually parallels what a real hacker would
1:31be going through.
1:32Most real hackers are maybe attacking through the internet,
1:35or maybe even if they're targeting me,
1:37they're going to have to try to learn and figure out
1:40what firewall vendor I'm using and what routing and switching
1:44vendor I'm using.
1:45Now access points they can walk around and see them
1:48and say, oh, yeah, you're using vendor B from an access point
1:51perspective, that's great, but we
1:54do need to understand that even though that's
1:57more accurate maybe to what an actual hacker would be going
2:00through it's not going to be as in-depth because they might not
2:03have discovered something simply because they didn't know
2:06something existed.
2:07So it's all about finding the balance.
2:09In a lot of situations, we probably
2:10want to do white box testing, but it definitely
2:13depends on the situation and what
2:15it is that we're trying to accomplish with our penetration
2:17test.
2:18Next question, what type of attack
2:20is being performed via the Evil Twin exploit?
2:23Well, remember what Evil Twin is all about?
2:25I've got my corporate access point here,
2:27and then we've got the bad guy access point over here.
2:32So this threat actor is trying to mimic the access
2:35point that is right nearby.
2:37This is why it's called an Evil Twin.
2:39We are the Evil Twin in this situation.
2:43I am truly trying to get these wireless stations
2:46to not associate to the corporate AP
2:48but rather to associate to my access point.
2:51If I can get you to associate to my access point,
2:54now I've become a man in the middle.
2:57And so E here would be the answer.
2:59At this point, I could hand this traffic
3:00off to the actual corporate access point,
3:02or maybe, in this situation, I can't adjoin
3:05the corporate access point.
3:06I don't have those credentials.
3:08I simply connect you out to the internet.
3:10And for the most part, this will get you
3:12everything you're looking for.
3:13So if you are trying to access internal resources,
3:15you wouldn't be able to get to those.
3:17And so, this user might just assume
3:18that the network resources are down
3:20or whatever the situation is.
3:22But the point here is that once we're in this Man-in-the-Middle
3:25type of situation, I can intercept and read all of this
3:29traffic.
3:30I might think my wireless connection
3:32is encrypted and authenticated, and safe,
3:34but because this person has inserted themselves
3:36into the middle, they are circumventing
3:39a lot of the defenses that I had in place.
3:41So we need to do what we can to detect these Evil Twin access
3:44points, what we might more generically
3:46refer to as rogue APs.
3:48Talked about how we can do that using wireless IPS
3:51sensors and whatnot.
3:52We need to be looking for rogue access points
3:54and shutting them down as soon as possible
3:56to prevent this type of attack from occurring.
3:58Question 8, how can a hacker perform a Layer 2 Denial
4:01of Service wireless attack?
4:04So when we're talking about a Denial of Service attack,
4:06keep in mind this is an attack that's
4:07intended to shut down specific services.
4:10In our case, we're trying to shut down the wireless.
4:13And there's not nearly as much of a hard reason for hackers
4:18trying to perform DoS attacks other
4:20than just to do damage, maybe make a name for themselves,
4:23but they're not usually trying to steal assets from us
4:26during DoS attacks unless it's a distraction in a larger attack
4:29or something along those lines.
4:31Either way, our wireless environment
4:33is susceptible to two different types
4:34of Denial of Service attacks.
4:36We can do Layer 1 Denial of Service attacks,
4:39or we can the Layer 2.
4:40And so when we, for example, see a hacker flood
4:44the area with wireless signal energy,
4:46well, what we're doing at this point is we're just making it
4:49so that nobody else can use the wireless.
4:52I'm just communicating out as loudly is I can,
4:55and I'm just sending my signals out there.
4:57And all of these other devices that
4:58are trying to use the wireless are
5:00unable to do so because I never stop talking.
5:03And so they're all waiting for me
5:05to stop talking so they can gain access to the medium.
5:08And because I never do, this becomes a Layer 1 Denial
5:11of Service attack.
5:12It's Layer 1 because I'm attacking
5:14with the signal energy, not with any kind
5:16of MAC-level information.
5:19Now conversely, if I'm sending deauthentication messages
5:22to nearby stations, well, that is taking advantage
5:25of MAC layer operations.
5:27It's no longer about the signal, just overwhelming--
5:31making it so that their SNR is too low to communicate
5:35or otherwise making it so they never
5:37gain access to the medium.
5:38That's all Layer 1.
5:39Deauth messages are part of the 802.11 messaging framework,
5:43and so that's taking advantage of Layer 2 operations.
5:47So I send a bunch of deauth messages
5:49to the nearby stations.
5:50I mimic the access points MAC address.
5:53And so I just simply send out deauth messages,
5:55and I'm targeting these devices.
5:57I'm saying, hey, you're deauthenticated.
5:59Hey, you're deauthenticated.
6:00And every time they re-authenticate,
6:02I send another deauth message.
6:03This is why protected management frames
6:05are so important because otherwise, I'm
6:09completely vulnerable to this type of Denial
6:11of Service attack from a Layer 2 perspective.
6:14But deploying protected management frames
6:16and encrypting those protected or those management frames
6:19via PMF, this is how we can make sure that hackers can't just
6:23show up and start flooding the area with the authentication
6:26messages.
6:27Although keep in mind we can't stop them
6:28from flooding the area with Layer 1 signal energy.
6:32At that point, we would need sensors in place
6:34to pick up on something like this
6:35and try to go figure out physically what's
6:37going on by going site.
6:39Next up, which of the following technologies
6:41are considered to be RSN security?
6:44So we have this concept of the Robust Security Network.
6:49This came out of an 802.11 specification that is known
6:52as 802.11i.
6:54802.11i gave us WPA2, which is built on a few things.
6:59It's got TKIP in there for backward compatibility.
7:02It's got CCMP in there, which uses AES.
7:05TKIP, by the way, is still using RC4.
7:08And so when we look at RSN security,
7:11again, everything in the specification
7:13is qualified as RSN.
7:14Now these days, we know that TKIP is not considered secure.
7:18TKIP is very trackable in the same way
7:20that WEP is very trackable.
7:22So we don't want to use TKIP.
7:24And yet, because it's part of the RSN definition in 802.11i,
7:29TKIP is technically considered RSN security.
7:33So as far as our question is concerned here,
7:36B, C, and D are all considered to be RSN security
7:39technologies.
7:40The only technology that's not considered
7:42to be RSN at this point is WEP, and we
7:45refer to this as pre-RSN.
7:48Now also keep in mind we learned about TSN, Transition
7:52Security Networks.
7:53And this is a little bit dated at this point
7:55because we don't see a whole lot of WEP out there.
7:58But TSN was meant to bridge the gap between unsecured WEP
8:02environment and an RSN network, I guess,
8:07a robust security network.
8:09And so this allowed us to have WEP enabled along with TKIP.
8:12And as stations were software upgraded to use TKIP,
8:16eventually, we could shut WEP down
8:18and this would transition over to an RSN.
8:20So that's a little bit of terminology.
8:22Again, we don't expect to ever see WEP, in use.
8:25It's been long since deprecated.
8:27We shouldn't still have stations out there relying on it.
8:29But from a terminology perspective,
8:31if we do see TSN mentioned, it's talking about an environment
8:34that has pre-RSN in security in place, which,
8:37again, for the purposes of this conversation,
8:40really is just referring to WEP.
8:42Moving on, which EAP type requires certificates
8:45on both the station and the server?
8:47So we should have a good sense of the different EAP types
8:50that we can expect to be deploying
8:52into our wireless environment.
8:53And so, especially when we look at the first three
8:56EAP-TLS, PEAP, EAP-TTLS, we should
8:58have a really good understanding of the differences among these.
9:02Now ironically, differences among these,
9:04as I say that B and C, PEAP and EAP-TTLS,
9:07these are very similar to one another.
9:10And so, EAP-TTLS is more of an extension of EAP-TLS.
9:13PEAP was created by Microsoft, for example.
9:16But they accomplish the same thing
9:17they're going to put credentials inside of a tunnel.
9:21And this is how it works for both PEAP and EAP-TTLS, which
9:26allows us to use something like a username and password rather
9:29than certificates.
9:31And so EAP-TLS, this is the one that
9:34requires the most administrative overhead because it
9:36is going to require certificates on the server, which
9:39isn't a big deal.
9:40I just need one certificate there.
9:41But also the station, which is a big deal because now
9:44I need certificates on every wireless station that's
9:47associating to my network.
9:48It is highly secure.
9:50But again, it takes a lot of administrative overhead.
9:53And so A here would be the answer.
9:55EAP-TLS is where I'm going to have to install certificates
9:58onto my stations, whereas EAP-TTLS and PEAP those are
10:02going to use this tunnel concept to transmit something
10:05like a password, handshake, and challenge.
10:08EAP-FAST, by the way, that is a Cisco Systems protocol.
10:11It's going to use that pack that we mentioned instead of any
10:14of these other mechanisms.
10:15But we didn't drill into the details of that primarily.
10:17Let's just make sure that we are understanding that that's
10:20a Cisco Systems thing, and these other three EAP types,
10:23these are something that we probably
10:25expect to see more often.
Review Quiz 11-15
0:00[AUDIO LOGO]
0:05OK, question 11, which device in the 802.1X authentication
0:10process is the authenticator for a wireless login?
0:13We definitely want to make sure we understand the 802.1X
0:16authentication process and the different rules that we have
0:18in place.
0:19For the most part, when we've talked about 802.1X,
0:22it has involved a station over here,
0:25and the 802.1X word for this is supplicant.
0:28So remember that they both start with S If we
0:31need help remembering that.
0:32And then the access point here, the AP,
0:35again starts with the letter A. This is the authenticator.
0:39So if we ever need help remembering that,
0:40just keep that in mind.
0:41But we also did talk about a wired network.
0:45And on a wired network, we have the switch,
0:47which of course, starts with S and throws off
0:49our whole memorization scheme, but a switch
0:52is also going to be an authenticator
0:54if we are a wired station.
0:57So if I've got a station here and I'm wired into a switch,
1:01the station is still the supplicant,
1:03but the authenticator is now the switch,
1:05whereas an access point is going to wirelessly
1:07be the authenticator even though it's
1:09plugged into a switch on the back end, which eventually both
1:13of these should end up talking to an authentication server
1:16over here somewhere.
1:17So make sure we understand the terms, the roles
1:20that we're assigning to all of these different devices,
1:22and make sure that we also differentiate between wireless
1:25and wired topologies.
1:27So given the question here, it's asking about a wireless login.
1:31So our authenticator is not a switch.
1:32It is an access point.
1:34The access point will facilitate communications back and forth
1:37between the station and the RADIUS server.
1:39So basically, the only thing we can communicate with up front
1:42is going to be our authenticator.
1:44Even though I maybe go through the 802.11 authentication
1:48association process, but I can't go anywhere on the network.
1:52I can just continue to communicate
1:53with the authenticator as it hands my credentials
1:56to the authentication server, maybe as a password challenge
1:59type of message is sent from the authentication server
2:03down to the supplicant.
2:04Again, the authenticator is just going to be sort of the call it
2:08the middleman at that point is going to be handing messages
2:11back and forth in order to facilitate the 802.1X login.
2:15Question 2, what security mechanism
2:17is deployed when using WPA-3 enterprise mode?
2:21So we may recall that WPA supported
2:24this TKIP and RC4 mechanism.
2:27Remember, RC4 is the cipher.
2:29We had a bunch of stations that were designed to use weapon
2:31software by RC4 and hardware.
2:33And so when WEP failed on us, we wanted
2:35to keep the hardware component because we
2:37had all these devices out there that required that,
2:39but we wanted to patch in software upgrade to TKIP.
2:43Now WPA-2 released, and it also supported WR, TKIP, and RC4.
2:48Not WEP.
2:49But then it introduced this wonderful new concept
2:52CCMP with AES 128-bit.
2:54Now when we're talking about WPA-3,
2:56we might get excited and say, all right,
2:58WPA-3 upgraded to GCMP and AES-256.
3:02And while it technically does give us that option,
3:05it's part of that mode that we call 192-bit operation.
3:09If we're running in 192-bit mode,
3:10not only do we have to use this new method GCMP and AES-256,
3:15but we also have to use EAP-TLS, as we recall,
3:18which requires certificates on both sides.
3:20And so this is pretty intense.
3:22I mean, not only are we talking about certificates,
3:25we're talking about using AES-256,
3:27which is going to be very hard on a lot of different stations
3:30that are out there unless they're purpose-built for it.
3:33And so this is something that's used
3:34for highly secure environments.
3:35But if I'm just trying to deliver WPA-3 security
3:38to my corporate world, I'm probably
3:40just going to rely on enterprise mode, not 192-bit mode.
3:44And so, at this point, enterprise mode
3:46is actually going to continue to use CCMP and AES 128-bit.
3:51This might come as a surprise to a lot of folks who
3:53are first learning wireless.
3:54I know it was for me when WPA-3 came out because I was used
3:58to this progression where we had WPA, WPA-2--
4:00I didn't write the two there.
4:02WPA had its method.
4:04WPA-2 had its methods.
4:06And it just sort of thought that WPA-3
4:08would have its new methods.
4:09And again, sometimes our eyes lock onto the new method,
4:12and this is maybe what we expected to have happen.
4:14And even though, again, we do have that option
4:16via 192-bit mode, technically speaking,
4:19when we're just talking about enterprise operation.
4:21There isn't a whole lot that changes.
4:23WPA-3 really introduced SAE as a big change as well as
4:27the 192-bit operation, but it didn't do a whole lot for us
4:31from an enterprise mode operation.
4:33We're talking about EAP.
4:34Big thing there is we don't have to worry anymore
4:36about the crack vulnerability, which is really good.
4:39That actually impacted WPA-2, for example.
4:41And it doesn't impact WPA-3.
4:43But as far as the underlying mechanisms are concerned,
4:46CCMP and EAS 128 are both still considered highly secure,
4:50and so we are comfortable relying on them
4:52for WPA-3 enterprise mode operation.
4:55Question 13, why is the SAE method considered
4:57to have Forward Secrecy?
4:59Forward Secrecy is kind of an interesting phrase.
5:04What we're saying here is that if you compromise my encryption
5:07keys today and I'm using WPA-2, then what you really did
5:11is you compromised my PTK, and you can probably
5:14use that to not only decrypt all of my future sessions
5:19but also decrypt all of my past sessions
5:21because you can just go back in time and use
5:23that PTK to decrypt everything.
5:25Whereas with SAE, we call it Forward Secrecy
5:27because I only use those encryption
5:29keys for a single session.
5:30I establish a new encryption keys
5:32even though my SAE passphrase doesn't change.
5:36My PSK password, if you get that key,
5:38you can forever decrypt everything
5:40because all you have to do is listen
5:42in to the four-way handshake, and you're
5:44going to be good to go there.
5:45Whereas with SAE, you can have this passphrase.
5:47It doesn't give you access to my encryption keys.
5:50And even if you do get my encryption keys,
5:52I'm only using them once.
5:53So it's not going to work in the future.
5:55And even though we call it Forward Secrecy,
5:56you can't actually use it for past traffic
5:59that you have captured, either.
6:00And so when we look at the answers that are given here,
6:04the answer is actually D. It's the fact that it
6:06uses new keys for each session.
6:09And that's because we use Diffie-Hellman in order
6:11to accomplish this.
6:12I'm not relying on the SAE passphrase.
6:15It has nothing to do with my encryption keys.
6:17I establish fresh new encryption keys
6:19with the access point every single time
6:21I create a new session.
6:23And so even if by some miracle you either
6:25guess the encryption key, which is statistically impossible,
6:28more likely you somehow get onto my machine,
6:30and you extract the encryption keys using maybe malware
6:33or something along those lines, at that point,
6:35you've got my encryption keys, and you can decrypt my traffic.
6:38But that's not going to work unless you get my encryption
6:41keys tomorrow because the encryption keys will change.
6:44Onward and upward here.
6:45Next question.
6:46What does OWE accomplish for wireless hotspots?
6:49Well, this should absolutely be a strong takeaway
6:51from our course here.
6:53We should know what Opportunistic Wireless
6:55Encryption is all about.
6:57The idea here is that I've got an open environment.
6:59I want it to be an open network because I want everybody
7:02to be able to very easily and seamlessly join my network.
7:05Maybe I'm a store, and I want my dozens
7:08of guests, my dozens of customers who are here
7:11at any given time to be able to very quickly join the wireless.
7:14And if I have to use a pre-shared key,
7:17whether it's WPA-2 or WPA-3 with an SAE, either way,
7:22this is going to take a whole lot of administrative overhead.
7:25I'm going to have to deal with the fact
7:27that customers are going to be asking me for this,
7:29and I want them to use my Wi-Fi.
7:31So let's just make it open.
7:33The problem with open is traditionally,
7:35this means that we get no encryption
7:37because we were relying on the PSK or the SAE process
7:41in order to give me encryption keys.
7:43So OWE is going to say, you know,
7:45what let's now longer bind these two things together.
7:48We've got an open network, but we can still
7:50use Diffie-Hellman to generate encryption keys.
7:53And once we generate those encryption keys,
7:55we can encrypt our traffic even if there was no authentication.
7:59And so, ultimately, the answer here
8:01is going to be A. It delivers encryption for open networks,
8:04and specifically, when we say open,
8:06we're saying that there's no authentication required.
8:09I do not need to provide a PSK or an SAE.
8:12I don't need to use a captive portal to log in.
8:15I can simply connect to the network
8:17and still be protected from eavesdropping via encryption.
8:21All right, question 15, and this is important here.
8:23We're going to match each component
8:25to the four-way handshake message that carries it.
8:28And this is a question that's really
8:30designed to make us stop and think,
8:32can I identify exactly how the four-way handshake operates
8:35and what each one of those four messages looks like?
8:38And so what we need to do here, let's go through this process.
8:41Now one of the first questions we need to ask
8:43is, I've got a supplicant and on authenticator.
8:46Who initiates the four-way handshake?
8:48And the answer is the authenticator.
8:50So our access point is going to trigger this
8:53by sending message one down.
8:55And because it's sending message one,
8:58it's going to send a nonce that belongs to the authenticator.
9:01So this is going to carry the Anonce.
9:04So this would be message one.
9:06Next, the supplicant is going to respond with message two,
9:10and it's going to include the supplicant nonce or the Snonce.
9:13Now keep in mind at this point, the supplicant already
9:16has generated the PTK after message one
9:19because it has all of the information.
9:21It already knows its own Snonce.
9:22It has the PMK, and now it has the Anonce plus all the MAC
9:27addresses.
9:27So we've got enough information.
9:29Generate the PTK.
9:30I send the Anonce back in message two--
9:33or the Snonce back in message two.
9:36There we go.
9:36And now, the authenticator can generate the PTK.
9:39Now we need to worry about that multicast in broadcast
9:43type of encryption.
9:44We've got multidestination traffic
9:45to concern ourselves with.
9:46So we're going to send the GTK in message three.
9:50So that would be message three.
9:52And Then message four.
9:54We are not going to send the PTK.
9:56That was a little bit of a trick question or trick
9:58option in there.
9:59We are never sending the PTK.
10:01That would completely eliminate the point
10:03of this whole process.
10:04I'm independently generating the PTKs.
10:07But keep in mind the whole point of this
10:08also is that I generate the exact same PTK on both sides.
10:12So once the supplicant derives it,
10:16and the authenticator derives its own,
10:17those two, if we could look at them side by side,
10:19they would be the exact same, which
10:21is why we can encrypt and decrypt using this key.
10:24And so the last message is simply
10:26an acknowledgment of sorts.
10:27It's basically saying, OK, those keys are installed.
10:30As part of message three, I also said
10:32to install these keys so they get installed.
10:34And I send message four back saying we're all good.
10:37Now do also keep in mind from a frame exchange perspective
10:40that each one of these messages does receive an 802.11
10:45acknowledgment.
10:46And so if any one of these messages goes unacknowledged,
10:49then the station that sent that message will send it again.
10:54So this is the four-way handshake.
10:56Again, we should absolutely know this process down
10:59if you were trying to remember which message carried
11:02the Anonce versus the Snonce or if the authenticator sent
11:05first, the supplicant set first, then
11:07make sure you take the time to review this and make sure we
11:10understand it before going and taking the CWSP
11:13as the four-way handshake is a big part of wireless security.
Review Quiz 16-22
0:00[AUDIO LOGO]
0:05All right.
0:06Question 16.
0:06We are getting down to the homestretch here.
0:08When does OWE perform its Diffie-Hellman exchange
0:12to derive encryption keys?
0:13And by the way, what about SAE?
0:15So let's start with OWE since that's
0:17the focus of the question.
0:19The answer here is actually going
0:20to be B. We are using the association frames
0:24and hijacking them, so to speak, and including
0:26Diffie-Hellman exchange information
0:28inside of those frames.
0:29What's interesting about OWE is that we
0:32have the typical authentication frames that go back and forth
0:35and these are unmodified.
0:36But then I'm going to have a slightly modified association
0:40frame or a set of frames go back and forth
0:42that include Diffie-Hellman in here.
0:44But the whole thing is still only four frames because we're
0:47only leveraging two separate frames
0:49for this Diffie-Hellman exchange,
0:51and that is what generates our encryption keys.
0:53Now SAE is very different.
0:55As let's see here-- this is OWE here.
0:57So SAE is going to hijack the authentication frames.
1:02And so, in this case, we're actually
1:04going to convert this over to four authentication frames.
1:08And so we're using this for the full Diffie-Hellman exchange
1:11in here.
1:12And then we've got phrases to refer to these
1:15as, for example, the SAE commit for the first two,
1:18and then the SAE confirm for the second two.
1:21And then, we perform the normal 802.11 association frames
1:25down here.
1:26So it's fascinating to see that SAE actually
1:29requires six total frames because it
1:31expands the authentication process to include four total.
1:35But do understand the difference here
1:37that SAE is going to leverage the authentication frames
1:40for including this Diffie-Hellman exchange.
1:41Whereas OWE is going to leverage the association frames.
1:44Now let's do what we can to try to keep those two concepts
1:47separated in our minds.
1:49Next question.
1:50What was one way that TKIP patched WEP to improve
1:53on its security?
1:54So once again, we understand, at this point,
1:56I think we said it quite a few times throughout the course
1:58that TKIP was a software upgrade for WEP
2:01because the protocol itself was the bigger problem, not
2:04the encryption cipher.
2:06And the P I underline there stands for protocol.
2:08So that's what we're sitting here talking about.
2:10So TKIP is still going to rely on RC4 in the same way
2:13that WEP did.
2:14And so we're not actually changing out the cipher.
2:16That might be a misconception out there
2:19that we just wanted to encrypt better,
2:21and so we used a stronger cipher.
2:22Not the case.
2:23In fact, we needed our hardware that existed out
2:26there to continue to run RC4.
2:28Instead, what it did was it lengthened the IVs,
2:31the initialization vector to be 48 bits.
2:34The biggest problem with WEP and it
2:36had a few different problems, but the biggest problem
2:39was that its IVs would repeat.
2:42And we talked very high level about the fact
2:45that when it comes to encryption,
2:47when we have lots of repeated phrases using
2:51the exact same encryption key, whether the message is
2:54very long or we reuse that key over and over again,
2:57that gives us patterns that we can recognize
3:00and we can use it to figure out what that key was.
3:03We do not want to give anybody listening in the ability
3:06to have--
3:08the ability to recognize patterns because they
3:11have so much information in front of them.
3:13And so, 24 bits seemed like a lot
3:15because that gave us millions of IVs,
3:17but a wireless device was able to cycle
3:20through those IVs in a very short amount of time.
3:22Really just hours of time, which is kind of crazy.
3:25And so by extending it to 48 bits,
3:28that sounds like we're doubling it,
3:29but we're actually taking it from 2 to the 24 to 2
3:32to the 48, which is a vast exponential increase
3:35in initialization vectors.
3:37And so that is how TKIP--
3:39again one of the ways that TKIP patched wep.
3:42It also-- keep in mind that it integrated the IV into the key
3:45rather than just appending it and sending it out in the open.
3:49Question 18.
3:50Which two mechanisms are designed to prevent
3:52man-in-the-middle attacks on wired networks?
3:54Yes, this is a wireless exam, but we
3:56want to be well-rounded security engineers.
3:59And furthermore, our wireless networks
4:01connect into the wired environment.
4:03And so it all comes together, and we
4:04need to make sure that we see the end-to-end picture here.
4:07So we spent some time on wired networks,
4:09and we talked about these mechanisms.
4:10Port security allows me to look at layer two Mac addresses
4:13and try to decide whether somebody should be allowed
4:16to be plugging in there.
4:17802.1X is a great solution for making sure only authenticated
4:22users are able to access the network,
4:24VLANS for segmentation.
4:25But D and E here.
4:27DHCP trust and dynamic ARP inspection,
4:29these are the two methods that we can use to prevent
4:32man-in-the-middle attacks.
4:33On the wired side, man-in-the-middle attacks--
4:35there's two very common ways to do this.
4:38One is by creating a rogue DHCP server.
4:41And I hand out a default gateway address that points to--
4:44near the default gateway, points to the threat actor's machine.
4:48And so that's one way of doing it.
4:50DHCP trust can eliminate the ability for a hacker
4:55to deploy a rogue DHCP server.
4:57The other option is for the bad actor here,
5:00the threat actor, to send out an ARP response that says hey,
5:04I know you're asking where your default gateway is,
5:06guess what, it's me.
5:07You send all of your traffic to me.
5:09I am your default gateway.
5:10This is known as ARP poisoning.
5:12And so we want to prevent ARP poisoning, and the way
5:15we do that is with dynamic ARP inspection.
5:18And remember that dynamic ARP inspection
5:20does rely on DHCP snooping.
5:23I know it sounds DHCP spoofing and snooping.
5:25They kind of sound similar, but snooping
5:28like I'm investigating, or I'm listening in.
5:30That's exactly what the switches will do.
5:32They'll snoop in on messages.
5:34They'll learn IP to Mac bindings.
5:36And they'll make sure with dynamic ARP inspection
5:38that you're not violating these IP to Mac bindings.
5:41And since we know that you don't actually
5:43own the Mac address for the default gateway,
5:45we're not going to let you tell people that you are.
5:48Question 19.
5:49What are two ways that 802.11r fast transition is different
5:53from OKC, which is opportunistic key caching.
5:57So both of these methods, the goal
6:00here is to create a fast, secure roaming environment.
6:03The problem is that when my station roams from one access
6:07point to another, if I have to perform any kind of EAP
6:11messaging in order to log in, then
6:13I have to repeat this process.
6:14I did it once over here, and now I have to do it again
6:17to authenticate and then generate those keys.
6:20And so, the goal here is to very quickly get
6:23a PMK on this access point so that we can generate PTKs.
6:28And if we can generate the same PTKs,
6:30that means we're authenticated, and we
6:31can bypass the EAP process.
6:34So it's all about how do I get this PMK on there.
6:36So we look at the fact that, yeah PMK is
6:39shared for quick PTK creation.
6:40Yeah, that's true for both of these.
6:42But they're not-- it's not different between the two,
6:44and so that's not a good answer here.
6:46The PMK being split into R0 and R1 variants,
6:50that is absolutely how 802.11r operates.
6:54Whereas OKC is going to pre-emptively and proactively
6:58cache the PMK on all the access points in the area and use PMK
7:02ids in order to prove that we have the same PMK.
7:05So that is not something that 802.11r does.
7:09Now something else it doesn't do,
7:10which is actually a good thing, is
7:11that it doesn't do the four-way handshake.
7:13It actually eliminates the need for the four-way handshake
7:16by performing this over the air or possibly over the ds
7:20transition or fast transition, which
7:23shares the nuances in advance.
7:24And so it's a great way to bypass the handshake.
7:27It actually makes it even faster than a PSK-type
7:30of re-association process.
7:32Where we do have to repeat the four-way handshake
7:34as fast as that is, we can eliminate that
7:37and be even faster.
7:38And so, saying that the overall roaming process is sped up
7:41is, once again, a goal for both of these
7:43to deploy fast, secure roaming.
7:45And so B and C here would be the answers for how 802.11r FT is
7:49specifically different from OKC.
7:52Question 20.
7:52How can guest network devices be protected from one another
7:56on an open network?
7:57Choose two.
7:58This concept comes back to the idea
8:00that it can be easy for a security engineer
8:03to say my primary goal is to keep
8:06my guests separate from my internal network.
8:10And that is absolutely arguably the biggest priority
8:13that we have when it comes to guest networks.
8:16The problem is that we do owe our guests
8:19some amount of security that--
8:21from each other.
8:22When they're accessing our network,
8:24we want them to be in a secure place.
8:26And the problem is that we can have legitimate guests on here,
8:29and we can also have threat actors who
8:31have joined the guest network.
8:33But how can we keep our guests safe from threat actors just
8:36using the guest network to attack other stations?
8:39Well, we can't really use separate VLANS for that.
8:41We're usually going to assign a single VLAN to our guests.
8:44But even if we have multiple VLANS,
8:46you're always going to have more than one station
8:49on a single vlan, so that doesn't help us out here.
8:52Host isolation.
8:53This is absolutely one of our choices
8:55because if I have a bunch of guest devices on the guest
8:59network, there's really no reason for those guests
9:02to be able to communicate with one another.
9:04They're usually all just trying to get to the internet and so
9:07why allow them to communicate with each other.
9:09So we simply say you're not allowed
9:11to communicate with one another, and that pretty quickly drops
9:14a threat actors ability to launch attacks
9:16on fellow guests.
9:18Now the other thing that we can do to protect them
9:20is by deploying OWE if this is an open network,
9:23as the question stated.
9:25A big problem with open networks is that we can listen in,
9:28and threat actors can just sit there
9:29and eavesdrop on conversations.
9:31So, again, we owe them some amount of protection.
9:34That would just be the responsible thing to do.
9:36And so, we could deploy OWE encryption
9:38recognizing that we could deploy PSK,
9:41but if there's one takeaway we should have from this course
9:43is that PSK protection is very low.
9:46It doesn't take much for an authenticate-- or a threat
9:49actor to gain access to the pre-shared key.
9:52And once they have access to the pre-shared key, I get on,
9:55or I sit there I send a d-off message to your station,
9:58you re-associate do the four-way handshake,
10:01I've got your PTK now I can decrypt all your messaging.
10:04So sounds good to say, let's do PSK protection.
10:07It is not going to create any kind of real security
10:10mechanisms unless I can really keep that PSK safe.
10:13Now the guest anchor wireless Lan controller.
10:15That is, again, focused on protecting my internal network.
10:18It basically tunnels my guests through the internal network
10:21to the DMZ, where the internet lives.
10:24And so this is the idea here is that I
10:28will keep my internal network safe by transporting
10:30my guests into the DMZ.
10:32And that way, if a threat actor happens
10:34to log into the guest network, even at this point,
10:37they won't be able to turn around and attack
10:38my internal network because of my firewall boundaries.
10:42Question 21.
10:43It is the penultimate or the next-to-last question.
10:46For each of the following protocol pairs,
10:48identify the member that is considered secure.
10:51So I guess it's less of a question
10:52and more of a statement.
10:54Either way, when we look at each one of these pairs,
10:57we understand that, for example, SSL
10:59is no longer considered to be secure,
11:01but we should be going with TLS.
11:03And we still might hear people refer to SSL connections.
11:06Usually, they're referring to TLS.
11:07But hey, if we do find out we have
11:09SSL active in our environment, we
11:11should be doing everything we can to migrate over to TLS.
11:15It's been around for a long time at this point.
11:17HTTP and HTTPS.
11:19That s is probably a pretty good indication
11:21that we should be using HTTPS.
11:23A lot of us just know this or have a grasp
11:25of this because of web surfing.
11:27But do keep in mind that this goes beyond web surfing.
11:29We've got management interfaces that use HTTP,
11:32we have rest APIs that use HTTP, and so we
11:37should be disabling the insecure version of HTTP
11:39and using HTTPS.
11:41Telnet and SSH.
11:43Again-- here, let me cross HTTP off.
11:45Telnet is the insecure version of this.
11:49There is no encryption, there is no native authentication
11:52with telnet, whereas SSH has both of those.
11:54And then, we have SNMP version 2c and version three.
11:58The trend here is to cross off the one on the left
12:00and go with the one on the right,
12:01and that holds true even through the end.
12:03But do keep in mind SNMP is something
12:05that's used a lot out there for network management.
12:08Version 2c is very simple.
12:10It uses that community string concept
12:12that we just see all over the place.
12:15I mentioned as a consultant, I would
12:16log into people's networks and find SNMP version 2c
12:19even though version three has been out for a long time.
12:21But version three is more complex to deploy.
12:24That's no excuse for not deploying it.
12:26It's just the reality.
12:27And so if it's up to us and we can get into a network
12:31and see that there's version 2c there,
12:33we should be disabling version 2c
12:34and enabling version three to take advantage of the security
12:37mechanisms.
12:38Especially considering how critical of a protocol
12:41SNMP really is.
12:43All right.
12:43This is the last question.
12:45What is an example of functionality
12:47that can be expected from a wireless ips?
12:49So when we're looking at remotely wiping
12:51lost mobile devices, this is a function of the mobile device
12:55manager or MDM, so that's out.
12:57Providing high-fidelity alerting.
12:59A great function, but one that is
13:02going to be created by the Sim, not by our wireless ips,
13:05so that one is out.
13:06Detecting a deauthentication attack on the wireless.
13:09That looks pretty good.
13:11A wireless ips should be analyzing things
13:13from a layer one and a layer two perspective.
13:15And we mentioned that this deauth attack is a layer two
13:18denial of service attack.
13:19So that's looking good.
13:21C is probably our answer here.
13:22And when we look at D, detecting a denial of service attack
13:25on the firewall.
13:26That would be something that either the firewall
13:28or potentially a wired ips might pick up on
13:31but certainly not our wireless ips.
13:34That keep in mind we're deploying wireless sensors out
13:36into the environment to focus in on layer one and layer two
13:40wireless operations.
13:41So that brings us to the end of a 22-question quiz.
13:45Be sure to, as always, go back and review whatever materials
13:49that this quiz helped identify as maybe being
13:52weak points in our knowledge.
13:54But otherwise, congratulations on completing the CWSP course.
13:57I hope this has been informative for you,
13:59and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year