PrepAway - Latest Free Exam Questions & Answers

Which action does the Wireless Intrusion Prevention System (WlPS) take when it detects that a device is sendin

Which action does the Wireless Intrusion Prevention System (WlPS) take when it detects
that a device is sending frames with a fixed initialization vector?

PrepAway - Latest Free Exam Questions & Answers

A.
captures the frames for future analysis

B.
logs the event

C.
deauthenticates the user

D.
adds the device to the dynamic blacklist

Explanation:
Flood attack refers to the case where WLAN devices receive large volumes of frames of the
same kind within a short span of time. When this occurs, the WLAN devices are
overwhelmed with frames from this device and consequently, frames from authorized
stations get dropped. IDS attacks detection counters this flood attack by constantly keeping
track of the density of traffic generated by each device. When this density exceeds the
tolerance limit, the device is reported to be flooding the network and will be blocked.
Subsequent frames from this device will not be processed. If the dynamic blacklist feature is
enabled, the detected device is added to the blacklist.
IDS detects the following types of frames:

l Authentication requests and de-authentication requests
l Association requests, disassociation requests and reassociation requests
l Probe requests
l Null data frames
l Action frames.


Leave a Reply