ALL PASS, NO FAIL!

CEH v13 Module 16: Hacking Wireless Networks — Free Practice Questions with Explanations

Last updated September 2026 · 10 questions · Module 16 of 20

Wireless attacks: WPA2 handshake capture and cracking, PMKID, WPS PIN attacks, evil twins, and WPA3 SAE. Exam focus: WPA2 cracking order is a classic — handshake capture, dictionary or PMKID attack, then deauth pitfalls. Know which 802.11 frames matter and how WPA3 SAE changes what an attacker can do offline.

⚠️ Important Disclaimer: These practice questions are original study material created by CEHStudy for educational purposes. They are NOT EC-Council exam questions and do NOT replicate the actual exam. CEHStudy is not affiliated with or endorsed by EC-Council.

Question 1: Compared with WPA2, WPA3 improves security primarily by adding:

Answer: D — SAE replaces the PSK 4-way handshake's offline-crackability; WPA3-Enterprise mandates 192-bit security suites (Suite B).

Question 2: The standard aircrack-ng workflow against WPA2-Personal is:

Answer: B — airmon-ng → airodump-ng (capture) → deauth → aircrack-ng -w wordlist.txt handshake.cap — offline cracking speed depends on hardware.

Question 3: An 'evil twin' attack involves:

Answer: C — Clients grab the stronger/more familiar signal and hand over credentials or sessions — tools: airbase-ng, hostapd, wifiphisher.

Question 4: A rogue access point is:

Answer: D — It bridges untrusted devices into the LAN — detect with WIDS/WIPS rogue-AP hunting and disable unauthorized bridging.

Question 5: War driving is:

Answer: D — Tools like InSSIDer and NetSpot log SSIDs, encryption, signal strength, and location — reconnaissance for later attacks or audits.

Question 6: Reaver and Bully are tools used to attack:

Answer: B — WPS's 8-digit PIN has a weak per-digit checksum, so offline attacks try ~11,000 combinations to recover it — disable WPS entirely.

Question 7: The PMKID attack on WPA2-Personal:

Answer: D — PMKID (hash of PMK + AP/client MACs) is sent in Association Response frames; with SSID known, hashcat can crack it offline.

Question 8: A deauthentication attack forces clients off a Wi-Fi network by sending:

Answer: A — Open (unencrypted) 802.11 management frames let anyone inject deauths — used in handshake capture; WPA3's PMF signs management frames to stop this.

Question 9: The strongest configuration for a WPA2-Personal home/office network is:

Answer: D — AES (CCMP) resists offline attacks best when paired with a high-entropy key; WPS and TKIP are broken/legacy — eliminate both.

Question 10: 'airmon-ng start wlan0' puts the wireless adapter into:

Answer: C — Monitor mode is prerequisite for airodump-ng capture — you see every frame, not just those addressed to your MAC.

Related Glossary Terms

Continue Your CEH v13 Prep

Frequently Asked Questions

How many CEH v13 Hacking Wireless Networks practice questions are on this page?

This page includes 10 original multiple-choice practice questions for CEH v13 Module 16 (Hacking Wireless Networks). Each question includes a detailed explanation of the correct answer and why the other options are wrong. The full CEHStudy question bank covers all 20 modules with 200+ questions — see the practice hub at https://cehstudy.com/ceh-practice-questions/ for every module.

What does CEH v13 Module 16 (Hacking Wireless Networks) cover?

Wireless attacks: WPA2 handshake capture and cracking, PMKID, WPS PIN attacks, evil twins, and WPA3 SAE. These are the same topics tested under this module on the EC-Council 312-50 exam. Pair this quiz with our free Module 16 flashcards at https://cehstudy.com/ceh-v13/module-16/ to close any gaps.

Are these real CEH exam questions?

No. Every question on CEHStudy is original study material written for exam preparation. They match the style, difficulty, and domain coverage of the actual CEH v13 exam but are not leaked or reproduced EC-Council questions.

How should I use this Hacking Wireless Networks quiz for exam prep?

Answer all 10 questions without peeking at explanations, then click "Show My Score". Review every explanation — especially the ones you missed — and re-test those topics with our free CEH flashcards. Aim for 80% or higher on module quizzes before scheduling the exam.

Where do I find CEH Hacking Wireless Networks flashcards?

Our free flashcard app covers all 20 CEH v13 modules including Module 16 (Hacking Wireless Networks). Visit the CEH flashcards page at https://cehstudy.com/ or the Module 16 page at https://cehstudy.com/ceh-v13/module-16/. No account or sign-up required.