- What This Cheat Sheet Covers (and Which Exam It Targets)
- Exam Logistics at a Glance
- The Four Domains and Where the Points Are
- 802.1X, RADIUS, and the EAP Method Cheat Table
- WPA3, OWE, and RSN Override
- Key Hierarchies and Handshakes
- Fast Roaming and Secure Guest Access
- Threats and Attacks Quick Reference
- Security Policy and Lifecycle: The 20% Candidates Underestimate
- Validity, CE, and Renewal Facts
- Scheduling the Domains Across Your Prep Weeks
- Frequently Asked Questions
- The current exam is CWSP-208 (2025 objectives): 60 multiple-choice questions, 90 minutes, 70% to pass.
- WLAN Security Design and Architecture is 50% of the exam; Vulnerabilities, Threats, and Attacks adds another 30%.
- A current, valid CWNA is required to earn CWSP, and the exam is delivered only through CWNP remote proctoring.
- Keep OWE separate from WPA3 authentication modes; mixing them up is a classic scenario-question trap.
What This Cheat Sheet Covers (and Which Exam It Targets)
This page is a compact review sheet for the Certified Wireless Security Professional credential issued by CWNP (Certified Wireless Network Professional). It is built around the CWSP-208 exam, which uses the 2025 objectives. The previous version, CWSP-207, ended on December 31, 2025, so any question bank, flashcard deck, or study guide that is explicitly tagged to CWSP-207 or the older CWSP-205 should be treated as unreviewed material until you have compared it against the current objectives.
One small wrinkle worth knowing: CWNP's credential page gives December 2025 as the CWSP-208 release month, while its exam-update table says November 2025. Both sources agree that CWSP-208 is the current exam and that the next version is scheduled for 2028, so the discrepancy does not change your study plan. If you want a broader orientation first, see What Is CWSP Certification? or the longer CWSP Study Guide 2026.
Exam Logistics at a Glance
These are the mechanics that candidates most often get wrong or discover too late. Confirm anything time-sensitive on the CWNP site before you pay.
| Item | CWSP-208 Fact |
|---|---|
| Issuer | CWNP |
| Format | 60 multiple-choice questions, one correct answer each |
| Time limit | 90 minutes (timer keeps running during approved breaks) |
| Passing score | 70% (80% for instructors) |
| Language | English |
| Voucher | USD $349.99, one attempt, valid two years from purchase or until the exam version ends, whichever is earlier |
| Delivery | CWNP remote proctoring only (not Prometric or Pearson VUE) |
| Prerequisite | A current, valid CWNA |
| Retake wait | 10 days, including weekends; another voucher required |
| Training | Instructor-led training is optional |
Remote-Proctoring Rules to Memorize
- Delivery runs through Google Meet alongside the CWNP Learning Center.
- You need matching, unexpired, government-issued photo identification.
- A working camera and microphone are required, and you may use only one monitor.
- Notes, outside assistance, external devices, and unrelated applications are prohibited.
- Approved breaks do not pause the clock.
Because the voucher expires at the earlier of two years or the end of the exam version, do not buy it years ahead of your intended test date. For the full dollar picture, including what else you may spend, read CWSP Certification Cost 2026; for prerequisites, see CWSP Requirements 2026.
The Four Domains and Where the Points Are
The official CWSP-208 objectives define four weighted domains. Weighting should drive your time allocation more than your personal comfort zone does.
| Domain | Weight | Character of the Questions |
|---|---|---|
| Domain 1: Security Policy | 10% | Policy elements, risk, compliance, and how policy drives technical choices |
| Domain 2: Vulnerabilities, Threats, and Attacks | 30% | Recognizing attacks, mapping them to mitigations, assessing exposure |
| Domain 3: WLAN Security Design and Architecture | 50% | Scenario-heavy design: authentication, encryption, roaming, guest access |
| Domain 4: Security Lifecycle Management | 10% | Monitoring, auditing, change management, and ongoing assessment |
With 60 questions, a 50% domain means roughly half the exam asks you to design or select the right architecture. For a deeper breakdown of each content area, see CWSP Exam Domains 2026: Complete Guide to All 4 Content Areas.
802.1X, RADIUS, and the EAP Method Cheat Table
This is the heart of Domain 3. You should be able to name every component in an 802.1X/EAP exchange and say which device talks to which.
The Three Roles
- Supplicant: the client device requesting access.
- Authenticator: the access point or controller that blocks the port until authentication succeeds.
- Authentication server: typically a RADIUS server that makes the access decision.
The authenticator relays EAP messages between the supplicant and the RADIUS server; it does not itself decide who is allowed in. Questions often hinge on exactly this distinction, such as where a certificate must be installed or which device holds the shared secret with the RADIUS server.
| EAP Method | Server Credential | Client Credential | Scenario Fit |
|---|---|---|---|
| EAP-TLS | Server certificate | Client certificate | Highest assurance; requires PKI that can issue and manage client certificates |
| EAP-TTLS | Server certificate | Typically credentials inside a TLS tunnel | Tunneled inner methods; no client certificate necessarily required |
| PEAP | Server certificate | Typically credentials inside a TLS tunnel | Common in directory-integrated environments; depends on correct server certificate validation on clients |
What to Be Able to Reason About
- Why server certificate validation on the supplicant is what defends tunneled methods against rogue authenticators.
- Why EAP-TLS removes password-based credential theft from the picture but raises certificate lifecycle workload.
- How RADIUS attributes can deliver authorization outcomes such as VLAN assignment or role.
- The difference between per-user and per-device authentication in policy terms.
WPA3, OWE, and RSN Override
WPA3 is easy to over-simplify. The exam rewards candidates who keep its parts distinct.
Keep OWE Separate from WPA3 Authentication Modes
Opportunistic Wireless Encryption (OWE) provides encryption for open networks without authenticating the user or the network in the way a credentialed mode does. It is not a WPA3 authentication mode and should not be filed alongside the personal and enterprise authentication options. When a question describes a public network where the goal is to protect over-the-air traffic from passive eavesdroppers without distributing a password, OWE is the concept in play; when it describes proving identity, you are in a different part of the architecture.
| Concept | What It Does | What It Does Not Do |
|---|---|---|
| OWE | Encrypts open-network traffic via an unauthenticated key exchange | Does not authenticate the user or verify the network's identity |
| WPA3 authentication modes | Authenticate stations to the network (personal and enterprise variants) | Are not interchangeable with OWE |
RSN Override
RSN Override is on the CWSP-208 emphasis list, so know what problem it addresses: letting a network advertise newer security capabilities in a way that supports coexistence with older client behavior during migration. Treat it as a transition-and-compatibility topic, and study how it interacts with the RSN information element and mixed-capability client populations. Do not rely on vague memory here; read the relevant CWSP-208 objective language and make sure your study material is current.
Key Takeaway
When an answer choice mentions WPA3, ask which mechanism the question is really about: authentication, encryption of an open network, or a migration/compatibility feature. The wrong options are often correct statements about a different mechanism.
Key Hierarchies and Handshakes
Candidates frequently memorize handshake names but cannot say what each message achieves. Study the hierarchy as a chain: a master key is established through authentication or a pre-shared credential, a pairwise key hierarchy is derived from it, and the 4-way handshake confirms both sides hold the same keying material and delivers the group key material for broadcast and multicast protection.
- Pairwise keys protect unicast traffic between one client and the AP.
- Group keys protect broadcast and multicast traffic and are shared across the BSS.
- Nonces from both sides ensure fresh key derivation for each session.
- Key distribution differs between enterprise (derived from the EAP-established master key) and personal modes (derived from the credential and network name).
Be ready to explain why rekeying matters, what a successful handshake proves, and how a failed handshake manifests to the client. Scenario questions may describe a symptom, such as repeated association followed by disconnection, and ask which stage of the exchange is most likely failing.
Fast Roaming and Secure Guest Access
Fast Roaming
Full 802.1X re-authentication on every roam is slow enough to disrupt voice and real-time applications, which is why fast roaming mechanisms exist. For the exam, focus on the trade-off each mechanism makes: how much of the key hierarchy is reused or pre-distributed, where keys are cached or held, and what security properties are preserved or weakened. Understand the general approaches (cached key reuse, pre-authentication concepts, and 802.11r-style fast transition) and the infrastructure each one depends on, such as controllers or key holders that can distribute keying material among APs.
Secure Guest Access
Guest design is a favorite scenario topic because it blends several domains. Think in layers:
- Segmentation: isolate guest traffic from internal resources with separate VLANs, firewall policy, or tunneling to a controlled egress point.
- Onboarding: captive portals, sponsored access, or self-registration, each with different accountability.
- Encryption: decide whether over-the-air protection is needed, which is where OWE fits for open guest SSIDs.
- Controls: client isolation, bandwidth limits, and acceptable-use enforcement tied back to policy.
Domain 3 Mindset: Design Before Product
Questions in WLAN Security Design and Architecture rarely reward vendor trivia. They reward choosing the control that fits the stated requirement.
- Read the requirement first: identity assurance, ease of onboarding, legacy client support, or compliance.
- Eliminate options that solve a different problem, even if they are technically valid.
- Prefer the answer that addresses the root cause rather than masking the symptom.
Threats and Attacks Quick Reference
Domain 2 carries 30% of the exam, so build a mental table that pairs each threat with its enabling weakness and its best mitigation. The exact catalog is defined by the objectives, but the categories below recur throughout wireless security.
| Threat Category | Underlying Weakness | Mitigation Direction |
|---|---|---|
| Rogue or unauthorized access points | Unmanaged devices bridging to the wired network | Monitoring and detection, port security, policy enforcement |
| Evil twin / impersonation | Clients that do not validate the network or server identity | Mutual authentication, server certificate validation, user training |
| Eavesdropping on open networks | No over-the-air encryption | Encryption of open networks (OWE), VPN for sensitive traffic |
| Offline credential guessing | Weak shared credentials or weak tunneled-method configuration | Strong credentials, certificate-based methods, correct supplicant settings |
| Management-frame abuse and denial of service | Unprotected management frames | Management frame protection, monitoring, rapid detection |
| Social engineering and misconfiguration | Human and process gaps | Policy, training, change control, auditing |
The question style is usually "given this scenario, which attack is occurring, or which control best counters it." Practice recognizing attacks from symptoms rather than names. If you want a sense of how demanding the exam is overall, How Hard Is the CWSP Exam? covers difficulty in detail.
Security Policy and Lifecycle: The 20% Candidates Underestimate
Security Policy (10%) and Security Lifecycle Management (10%) together are one-fifth of the exam. They are less technical, which makes them look easy and tempting to skip. Do not skip them; they are among the more predictable sources of points.
Domain 1: Security Policy
Understand how written policy governs technical decisions rather than the other way around.
- How policy defines acceptable use, access rights, and incident expectations.
- How risk assessment and compliance requirements shape the chosen architecture.
- Why enforcement and accountability must be built into the design, not added afterward.
Domain 4: Security Lifecycle Management
Security is a continuing process, not a one-time deployment.
- Ongoing monitoring, auditing, and validation that controls still work.
- Change management and re-assessment when the network or threat landscape shifts.
- Feeding findings back into policy and design.
Validity, CE, and Renewal Facts
The standard CWSP credential is valid for three years. Renewal under the standard path requires a current CWNA and a pass on the current CWSP exam, which also renews CWNA for three years.
The Optional Professional CE Route
- You must elect it within one year of certification.
- It requires eight approved, documented CE hours annually plus annual renewal.
- The linked guidelines specify that two of those hours include passing the annual certification CE eLearning.
- Election cannot revert to the three-year testing cycle, and CE renewal does not itself renew CWNA.
For dates and scheduling context, see CWSP Exam Dates 2026. For the long-term value question, Is the CWSP Certification Worth It? and the CWSP Salary Guide 2026 discuss earnings and return qualitatively; this cheat sheet intentionally makes no salary or pass-rate claims.
Scheduling the Domains Across Your Prep Weeks
Because Domain 3 is half the exam, front-load it. Here is a sample sequence for a candidate who already holds a current CWNA and has a few weeks to prepare. Adjust the length to your own background.
Authentication Foundations
- 802.1X roles, RADIUS flow, and the EAP method table above.
- PKI basics: CA hierarchy, server and client certificates, revocation.
Encryption, Keys, and WPA3
- Key hierarchy and 4-way handshake purpose of each message.
- WPA3 modes, OWE as a distinct concept, and RSN Override.
Roaming, Guest Access, and Threats
- Fast roaming trade-offs and guest design layers.
- Attack-to-mitigation mapping for Domain 2.
Policy, Lifecycle, and Timed Practice
- Domains 1 and 4 review, then full 60-question timed sets against 90 minutes.
- Rehearse remote-proctoring setup: ID, camera, microphone, single monitor.
Use practice questions written for CWSP-208 rather than recycled banks, and review every miss by asking which requirement in the stem you overlooked. You can start with the CWSP practice test and revisit the CWSP passing score breakdown to calibrate your target. Remember the 70% threshold is a score requirement, not a pass rate; for what is and is not known about outcomes, see CWSP Pass Rate 2026.
Frequently Asked Questions
CWSP-208, which uses the 2025 objectives. CWSP-207 ended on December 31, 2025, and CWNP schedules the next version for 2028. Avoid material tied only to CWSP-207 or CWSP-205 unless you have checked it against the current objectives.
A current, valid CWNA is required to earn the CWSP credential. Instructor-led training is optional. See the CWSP requirements guide for the eligibility details.
The exam has 60 single-answer multiple-choice questions in 90 minutes. The passing score is 70%, or 80% for instructors.
No. CWSP-208 is delivered exclusively through CWNP remote proctoring rather than Prometric or Pearson VUE. You need matching government-issued photo ID, a working camera and microphone, and a single monitor.
You must wait 10 days, including weekends, before another attempt, and a new attempt requires another voucher. The voucher covers one attempt only.
Start with What Is CWSP? for the definition and CWSP Jobs for how the credential is used in wireless security roles. Public sources for the facts on this page were checked October 5, 2026, and exam policies can change, so confirm anything critical with CWNP.