0% found this document useful (0 votes)
11 views4 pages

Mobile and Wireless Security Test 2025

Uploaded by

kr1553
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views4 pages

Mobile and Wireless Security Test 2025

Uploaded by

kr1553
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

SRM Institute of Science and Technology

College of Engineering and Technology


School of Computing
Department of Networking and Communications
Academic Year: 2025-26 (ODD)
SET- D

Test: FT3 Date: 24-10-2025


Course Code & Title: 21CSE489T- MOBILE AND WIRELESS SECURITY Duration: 100 minutes
Year & Sem: IV Year / VII Sem Max. Marks: 50

Course Articulation Matrix:


[Link] Course PO PO PO PO PO PO PO PO PO PO PO PO PO PO PO
. Outcom 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
e
1 CO1 2 - 3 - 3 - - - - - - - - - -

2 CO2 - - 3 - - - - - - - - - - - -
3 CO3 2 - 3 - - - - - - - - - - - 3
4 CO4 - - 3 - 3 - - - - - - - - - 3
5 CO5 - - - - 3 - - - - - - - - - -

Part – A: (10 x 1 = 10 Marks)


Instructions: Answer all Questions
Q. Question Mark BL CO PO PI
No s Code
1 Which of the following is an example of an active attack on 1 L2 3 1,3,1 2.8.3
a Wi-Fi network? 5
A. Sniffing beacon frames
B. Listening to unencrypted traffic
C. Replay of captured frames
D. Monitoring SSID broadcasts

2 The 802.1X standard provides: 1 L2 3 1,3,1 1.7.1


A. encryption of MAC frames 5
B. key management only
C. port-based network access control and authentication
D. frequency hopping for security

3 In 802.11i, the four-way handshake is used primarily to: 1 L3 3 1,3,1 1.7.1


A. exchange data frames 5
B. confirm mutual authentication and derive fresh
encryption keys
C. associate with an SSID
D. scan available networks

4 A Trojan attack in wireless context usually means: 1 L2 3 1,3,1 2.8.3


A. jamming the wireless channel 5
B. embedding malicious code inside a legitimate-looking
application
C. capturing authentication frames
D. sending deauthentication frames

5 The security mechanism in IEEE 802.11 that enforces “per- 1 L3 3 1,3,1 1.7.1
client access control” is: 5
A. WEP
B. WPA-PSK
C. 802.1X / RADIUS
D. TKIP

6 In the WiMAX architecture, what is the role of the "Base 1 L1 4 3,5,1 1.6.1
Station (BS)"? 5
A. Acts as a mobile subscriber
B. Provides connectivity to the backbone network and
controls radio resources
C. Acts as a simple repeater
D. Provides just authentication services

7 Which of the following is a vulnerability specific to IEEE 1 L4 4 3,5,1 2.8.3


802.16-2004 (fixed WiMAX)? 5
A. Rogue Base Station attacks
B. Denial of Service (DoS) via flooding RNG-REQ
messages
C. Replay attacks on authentication messages
D. All of the above

8 In UMTS, the “f8” function is used for: 1 L1 4 3,5,1 1.7.1


A. Generating integrity keys 5
B. Encryption (ciphering)
C. Hashing IMSI
D. Random number generation

9 What is a Denial of Service attack in WiMAX at the MAC 1 L2 4 3,5,1 2.8.3


layer often based on? 5
A. Overloading uplink with data
B. Flooding control frames like RNG-REQ or MOB_SCN
C. Jamming the frequency
D. Eavesdropping only

10 Which of the following is not typically protected by LTE 1 L4 4 3,5,1 1.7.1


security mechanisms? 5
A. Integrity of RRC signaling
B. Confidentiality of user data
C. Validity of MME to eNodeB messages outside core
D. Open broadcast channels
SRM Institute of Science and Technology
College of Engineering and Technology
School of Computing
Department of Networking and Communications
Academic Year: 2025-26 (ODD)
SET- D

Test: FT3 Date: 24-10-2025


Course Code & Title: 21CSE489T- MOBILE AND WIRELESS SECURITY Duration: 100 minutes
Year & Sem: IV Year / VII Sem Max. Marks: 50
Part – B: (4 x 5 = 20 Marks)
Instructions: Answer any 4 Questions
Describe the main security mechanisms of the IEEE 802.11
1,3,1
11 standard. 5 L2 3 1.7.1
5
Explain the working and importance of Layer 3 security
1,3,1
12 mechanisms in wireless networks. 5 L3 3 1.2.1
5
Explain the main features and security mechanisms defined
1,3,1
13 in the Bluetooth technical specification. 5 L2 3 1.7.1
5
Discuss the security risks involved in IEEE 802.16-2004
3,5,1
14 (Fixed WiMAX). 5 L4 4 2.8.3
5
Describe the security architecture of GSM and identify its
3,5,1
15 main vulnerabilities. 5 L2 4 1.7.1
5
Explain the main security threats and protection
3,5,1
16 mechanisms in VoIP systems. 5 L3 4 2.8.2
5
Part – C: (2 x 10 = 20 Marks)
Instructions: Either or Choice Type Questions
17(a) A university campus uses a WPA2-secured Wi-Fi network. 10 L5 3 1,3,1 2.8.3
Recently, several students complained about frequent 5
disconnections and slow connections. The network
administrator notices a large number of deauthentication
frames in the traffic logs and multiple rogue access points
with similar SSIDs.
As a network security analyst,

1. Identify and explain the type(s) of attacks occurring


in this scenario. [4 Marks]
2. Discuss how active and passive attacks could be
involved. [3 Marks]
3. Suggest appropriate countermeasures using IEEE
802.11i and 802.1X standards to mitigate such
attacks. [3 Marks]
OR
17(b) A team of researchers is testing Bluetooth communication 10 L5 3 1,3,1 2.8.1
between wearable health devices and smartphones. During 5
testing, they discover that some data packets can be
intercepted and that unauthorized devices can attempt
pairing using the “Just Works” mode.

1. Identify the security vulnerabilities in this


Bluetooth setup. [4 Marks]
2. Explain how Secure Simple Pairing (SSP) and link
key management improve security. [3 Marks]
3. Recommend best practices to prevent unauthorized
access and data interception in Bluetooth-enabled
medical devices. [3 Marks]
18(a) A city-wide WiMAX network (based on IEEE 802.16- 10 L5 4 3 2.8.3
2004) is being used to provide broadband access to public
offices. After deployment, users report frequent
disconnections and suspicious data interception. Security
analysis reveals lack of mutual authentication and replay
attacks on management messages. The network
administrators plan to upgrade to 802.16e.

1. Identify and explain the security vulnerabilities in


the original 802.16-2004 system. [4 Marks]
2. Describe how PKMv2 in 802.16e improves key
management and authentication. [3 Marks]
3. Discuss additional countermeasures (e.g.,
encryption and integrity protection) that should be
implemented to enhance overall security. [3 Marks]
OR
18(b) A multinational company uses VoIP over the public Internet 10 L5 4 3 2.8.3
for internal and customer communications. Recently, they
experienced call drops, fake call initiations, and leaked
voice recordings. The IT department suspects SIP message
tampering and media eavesdropping.

1. Identify the types of attacks affecting the


company’s VoIP system. [4 Marks]
2. Explain how TLS and SRTP can be implemented to
secure signaling and media transmission. [3 Marks]
3. Propose organizational and technical measures to
prevent such attacks in future (firewall rules,
authentication, encryption policies, etc.). [3 Marks]

Course Outcome (CO) and Bloom’s level (BL) Coverage in Questions

60 CO Coverage in % Bloom’s level (BL)


% %
50
Coverage
40

30
8% L1
20 L2
38% 24%
L3
10
L4
13%
0 19% L5
CO1 CO2 CO3 CO4 CO5

Approved by the Audit Professor/Course Coordinator

You might also like