Week 6: Mobile, Wireless, Firewall Evasion, and Social Engineering
Week of Sun, Sep 27 · week closes Sat, Oct 3
This week's items
- Weekly Quiz 6points in Canvas
- Discussion Board 6points in Canvas
- Lab 6points in Canvas
Exact due times are in Canvas. Late assignments are NOT accepted. Complete all assignments before the due date.
Read this week
- TestOut Ethical Hacker Pro — Ch 16–18 — Commercial text; named here for reference.
- Wi-Fi Alliance — WPA3 Security Overview — Free — covers SAE and WPA3 enterprise authentication.
Know these cold
- Wireless protocol strength: WEP (broken — RC4 IV reuse allows key recovery) → WPA (TKIP — improved) → WPA2 (AES-CCMP — current enterprise standard) → WPA3 (SAE — resists offline dictionary attacks).
- Evil twin attacks create a rogue access point with the same SSID as a legitimate network — clients connect automatically to the strongest signal.
- IoT devices frequently ship with default credentials, lack patch mechanisms, and transmit data unencrypted — creating persistent attack surface.
- Firewalls filter traffic by rules; IDS detects anomalous patterns and alerts; IPS detects and blocks in real time.
- Social engineering exploits human psychology: phishing (email), vishing (voice), smishing (SMS), and pretexting (fabricated scenario).
- Physical security assessment evaluates tailgating prevention, badge policies, and secure disposal — all require explicit written authorization.
- Standards: Maryland Blueprint Pillar 3 · CEH v12 Domain 13 (Wireless) + Domain 14 (IDS/Firewalls) + Domain 15 (Social Engineering) · PGCC Outcomes 2, 4, 5.
Meerk's quiz — open the Week 6 gate
10 questions, no time limit. 85% on your first attempt in a 24-hour window opens the gate. Retakes inside the window are practice — they help you learn, they don't count. Work alone; the point is to know it, not to have seen it.
Dinner Table Question
Ask at home: A security guard lets a delivery worker into a server room without badging. What attack does this enable, and what is the policy control?
En español: Un guardia deja entrar a un repartidor a una sala de servidores sin registrarlo. ¿Qué ataque habilita esto y cuál es el control de política?