Certified Ethical Hacker (CEH) Practice Question

During a wireless security assessment you discover that all office access points broadcast a WPA2-PSK network with Wi-Fi Protected Setup (WPS) PIN authentication still enabled. Because tools such as Reaver can recover the PSK in a matter of hours by brute-forcing the eight-digit PIN, which single countermeasure should you recommend first to most effectively eliminate this specific risk without requiring new hardware?

  • Disable WPS on all access points and require users to enter the pre-shared key manually when onboarding devices.

  • Reduce the WPS PIN length from eight digits to six digits to lower the attack surface.

  • Retain WPS and add MAC address filtering so only known device MACs can associate with the network.

  • Keep WPS enabled but change the WPA2 passphrase to a randomly generated 64-character string.

Certified Ethical Hacker (CEH)
Wireless Network Hacking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot