ExamRange

In this simulation, you will analyze wireless reconnaissance techniques used by attackers to map organizational perimeters. Learn to identify the signatures of access point mapping and understand the defensive controls required to secure wireless signals.

CND (312-38) Network Defense Simulation

Network Scenario

The organization operates a suburban campus with several branch offices. The internal network uses a WPA3-Enterprise wireless infrastructure (SSID: Corp_Secure_WiFi).

Physical security reports mention a slow-moving vehicle circling the perimeter multiple times over the last 48 hours. Simultaneously, the Wireless Intrusion Prevention System (WIPS) flagged several "Probe Request" bursts from unidentified MAC addresses originating outside the building line.

Traffic & Logs

# WIPS Alert Log - ID: 4492-W
[2023-10-24 14:22:10] ALERT: High-frequency Probe Requests detected.
[2023-10-24 14:22:11] Source MAC: 00:0C:29:XX:XX:XX (OUI: VMware, Inc.)
[2023-10-24 14:22:11] Targeted SSIDs: [ANY], [Corp_Secure_WiFi], [Guest_Net]
[2023-10-24 14:23:05] Signal Strength observed: -72dBm to -85dBm (fluctuating).
---
# Kismet Log Fragment (External/Simulated)
BSSID: AC:DE:48:00:11:22 | SSID: Corp_Secure_WiFi | CH: 6 | ENC: WPA3 | GPS: 34.0522, -118.2437
BSSID: AC:DE:48:00:11:23 | SSID: Guest_Net | CH: 11 | ENC: OPEN | GPS: 34.0523, -118.2439

Note: The logs show an external entity capturing BSSIDs, SSIDs, and signal strengths correlated with GPS coordinates.

Question

Which of the following techniques is also called access point mapping?