- What the Certified Wireless Security Professional Credential Is
- CWSP-208 Format, Fees, and Remote Delivery
- The Four Weighted Domains
- Architecture Topics You Must Master
- Threats, Attacks, and the 30% Domain
- The CWNA Requirement
- Cost, Salary, and ROI Without Guesswork
- Sequencing Your Preparation by Domain
- Validity, Renewal, and the CE Route
- Frequently Asked Questions
- CWSP-208 is the current exam: 60 single-answer multiple-choice questions in 90 minutes, with a 70% passing score.
- WLAN Security Design and Architecture carries 50% of the exam; Vulnerabilities, Threats, and Attacks adds 30%.
- A current, valid CWNA is required before the CWSP credential can be earned.
- The voucher costs USD $349.99 for one attempt, and the exam is delivered only through CWNP remote proctoring.
What the Certified Wireless Security Professional Credential Is
Certified Wireless Security Professional is a professional-level credential issued by CWNP (Certified Wireless Network Professional). It validates that you can design, secure, and defend enterprise WLANs, covering authentication infrastructure, encryption, threat detection, and the policy and lifecycle processes that keep a wireless network defensible over time. If you want the plain-language basics first, see What Is CWSP Certification? or What Does CWSP Stand For?.
This is not an entry-level certificate. It sits above CWNA in the CWNP track and assumes you already understand how 802.11 networks behave. The exam rewards candidates who can reason through architecture trade-offs, not those who memorize acronym lists. If you are comparing it with other security credentials, keep the identity straight: this article covers only the CWNP credential, and the exam facts here apply to nothing else sharing the abbreviation.
The current exam is CWSP-208, built on the 2025 exam objectives. CWSP-207 ended on December 31, 2025, so older question banks written for CWSP-207 or CWSP-205 should not be treated as a reliable picture of today's exam. CWNP's credential page and its exam-update table disagree slightly on whether CWSP-208 launched in December 2025 or November 2025, but both identify it as current and schedule the next version for 2028.
CWSP-208 Format, Fees, and Remote Delivery
| Item | CWSP-208 Detail |
|---|---|
| Issuer | CWNP |
| Questions | 60 multiple-choice, single correct answer |
| Time | 90 minutes |
| Passing score | 70% (80% for instructors) |
| Language | English |
| Voucher | USD $349.99 for one attempt |
| Voucher validity | Two years from purchase or until the exam version ends, whichever is earlier |
| Delivery | CWNP remote proctoring only (not Prometric or Pearson VUE) |
| Retake wait | 10 days, including weekends |
Two details trip people up. First, the voucher covers a single attempt; a second attempt requires purchasing another voucher. Second, because vouchers expire when the exam version ends, buying one far in advance of your readiness is a poor bet. For the full money picture, see the CWSP certification cost breakdown, and for scheduling logistics see CWSP exam dates and scheduling.
Remote Proctoring Rules
Remote delivery runs through Google Meet alongside the CWNP Learning Center. You need matching, unexpired government-issued photo identification, a working camera and microphone, and a single monitor. Notes, outside assistance, external devices, and unrelated applications are prohibited. The timer keeps running during approved breaks, so plan your 90 minutes as continuous.
The Four Weighted Domains
CWNP publishes the CWSP-208 objectives with four weighted domains. The weighting should drive how you allocate your time. For a deeper domain-by-domain walk-through, read the complete guide to all four content areas.
| Domain | Weight |
|---|---|
| Domain 1: Security Policy | 10% |
| Domain 2: Vulnerabilities, Threats, and Attacks | 30% |
| Domain 3: WLAN Security Design and Architecture | 50% |
| Domain 4: Security Lifecycle Management | 10% |
Half the exam sits in a single domain. A candidate who is strong on attack techniques but vague on how to architect an 802.1X deployment is exposed, because roughly half of the 60 questions will probe design decisions. The distribution also means Security Policy and Security Lifecycle Management, though smaller, are not free points; they tend to be scenario-based and punish guessing.
Architecture Topics You Must Master
Domain 3 questions are typically scenario-driven: a deployment constraint is described and you pick the design that satisfies it. Expect to reason rather than recall.
Domain 3: WLAN Security Design and Architecture (50%)
You need to move fluently between protocol mechanics and deployment judgment.
- 802.1X and RADIUS: supplicant, authenticator, and authentication server roles; what traffic is permitted before authentication completes; where the RADIUS exchange sits in the flow.
- EAP methods: EAP-TLS, EAP-TTLS, and PEAP, including which require client certificates, how the TLS tunnel is established, and what that means for credential exposure.
- PKI: certificate validation on supplicants, server certificate trust, and why misconfigured validation undermines an otherwise strong EAP method.
- WPA3: the distinct personal and enterprise modes, protected management frames, and how they change deployment and transition planning.
- OWE: keep Opportunistic Wireless Encryption distinct from WPA3 authentication modes; it provides encryption for open networks and does not authenticate users.
- RSN Override: know what it is and the problem it addresses in mixed-capability environments.
- Key hierarchies and handshakes: how the master key material derives the pairwise and group keys, and what the 4-Way Handshake and Group Key Handshake accomplish.
- Fast roaming: the security implications of key caching and fast transition mechanisms, and what must be preserved when a client moves between APs.
- Secure guest access: segmentation, captive portal considerations, and encryption choices for visitors.
Why Key Hierarchies Matter
Candidates often learn the handshakes as a sequence of numbered frames and then stumble when a question asks which key protects which traffic, or what happens to derived keys after re-authentication. Build a mental map: authentication produces master key material, the handshake derives transient keys, and separate keys protect unicast and group traffic. When you can explain the purpose of each key rather than its position in a diagram, scenario questions become far easier.
Threats, Attacks, and the 30% Domain
Domain 2 covers how wireless networks are attacked and how those attacks are recognized and mitigated. Treat it as defense-oriented: for each attack, know the weakness it exploits, the symptom it produces, and the control that closes the gap.
Domain 2: Vulnerabilities, Threats, and Attacks (30%)
Pair every attack with its countermeasure.
- Rogue and unauthorized access points, and how detection and containment differ
- Denial-of-service conditions against management frames and the role of protected management frames
- Eavesdropping and key-recovery attacks against weak or legacy configurations
- Evil twin and impersonation attacks, and why server certificate validation is the key defense on the client side
- Weaknesses of legacy security and why transition modes expand exposure
- Monitoring approaches, including what a wireless intrusion prevention system can and cannot see
The recurring exam skill is matching an observed symptom to the correct root cause and remediation. A question might describe a pattern of client disconnections and ask which control would have prevented it. Knowing a long attack list matters less than understanding the mechanism behind each entry.
Domains 1 and 4 in Practice
Security Policy questions ask you to connect policy requirements to technical controls, such as what a policy for BYOD, guest access, or acceptable use implies for network design. Security Lifecycle Management covers assessment, monitoring, maintenance, and ongoing validation. Together they are 20% of the exam, enough to decide a borderline result.
The CWNA Requirement
You must hold a current, valid CWNA to earn the CWSP credential. Instructor-led training is optional, so self-study is a legitimate path. If your CWNA has lapsed or is close to expiring, deal with that first because it affects both eligibility and the renewal strategy discussed below. The CWSP requirements guide walks through eligibility in more detail, and the CWSP training overview covers optional instruction.
The CWNA foundation matters beyond the paperwork. CWSP-208 assumes you understand frame exchanges, roaming behavior, and RF fundamentals well enough that security discussions do not require re-learning the basics.
Cost, Salary, and ROI Without Guesswork
The only fixed cost CWNP publishes for the exam itself is the USD $349.99 voucher. Your total outlay depends on study materials, any training you choose, a possible second voucher, and renewal costs. Build your own budget from those pieces; the cost breakdown helps with that.
On salary and return on investment, be skeptical of any single headline figure. Public salary data for this exact wireless-security credential is thin, and numbers attributed to similarly abbreviated certifications from other bodies do not apply here. A more reliable way to judge value is qualitative: this credential signals specialized wireless security depth to employers who run enterprise WLANs, such as organizations with large campus, healthcare, education, or distributed-site networks, and to consultancies and integrators who design and audit them. Explore the CWSP jobs overview, the salary guide, and the worth-it analysis for a structured way to weigh it against your own role and market.
Key Takeaway
Passing score and pass rate are different things. The 70% threshold (80% for instructors) is a published requirement; no reliable public pass rate for this exact credential should be assumed. See what you need to pass and what the pass-rate data does and does not show.
Sequencing Your Preparation by Domain
Because Domain 3 is half the exam and depends on protocol fundamentals, sequence your study so the foundational mechanics come first and the scenario-heavy material gets the most repetition. The timeline below is one reasonable ordering, not a guarantee; stretch or compress it to match your CWNA freshness and daily availability. For a fuller approach, see the CWSP study guide.
Authentication and Key Foundations
- 802.1X, RADIUS, and EAP method differences
- PKI concepts and certificate validation behavior
- Key hierarchies and the handshakes
Design Scenarios
- WPA3 modes, OWE, and RSN Override
- Fast roaming security trade-offs
- Guest access and segmentation designs
Attacks and Countermeasures
- Pair each attack with mechanism and control
- Monitoring and detection capabilities
Policy, Lifecycle, and Timed Practice
- Policy-to-control mapping and lifecycle processes
- Timed sets of 60 questions in 90 minutes
- Review misses by domain, then revisit Domain 3
When you review practice results, tag each miss by domain and by cause: did you not know the concept, misread the scenario, or choose a plausible but suboptimal design? The last category is the most common on this exam and the one repetition fixes. A one-page cheat sheet is useful for final-week review, and the difficulty guide can help you calibrate how much time you need.
Validity, Renewal, and the CE Route
Standard validity is three years. To renew by testing, you need a current CWNA and a passing result on the current CWSP exam, which also renews your CWNA for three years. That pairing makes renewal planning part of your original strategy rather than an afterthought.
The Optional Professional CE Route
CWNP offers a continuing-education alternative for this credential. Key rules to understand before electing it:
- You must elect the CE route within one year of certifying.
- It requires eight approved, documented CE hours each year plus annual renewal.
- The linked guidelines require two of those hours to include passing the annual certification CE eLearning.
- Election cannot be reversed to the three-year testing cycle.
- CE renewal does not itself renew your CWNA.
Frequently Asked Questions
CWSP-208, built on the 2025 objectives. CWSP-207 ended December 31, 2025, so avoid relying on unreviewed CWSP-207 or CWSP-205 question banks. Start with the domain guide to anchor your study to the current objectives.
The exam has 60 multiple-choice, single-correct-answer questions in 90 minutes. The passing score is 70%, or 80% for instructors.
No. CWSP-208 is delivered exclusively through CWNP remote proctoring, not Prometric or Pearson VUE. You need valid photo ID, a camera, a microphone, and one monitor.
CWNP's FAQ specifies a 10-day waiting period, including weekends, for this professional-level exam. Each additional attempt requires another voucher.
Yes. A current, valid CWNA is required to earn the credential. Instructor-led training is optional. See the requirements guide for eligibility details, or the main CWSP certification page for an overview.