Study Tips Learn how to use all aireplay modules and airodump at any given situation. Learn how to configure wireless card/usb into promiscuous mode and other card configuration changes. Learn to capture WPA 4way handshake from WPA networks. Learn to use dictionary attacks and brute-force attacks against WEP and WPA2 networks. Learn how to perform WEP attacks with and without any clients connected. Time yourself attacking a lab router. Practice report writing. Exam Tips Get a large glass of water to stay hydrated. Eat beforehand and/or keep a snack near your console. Keep your labs vm on-line to test (use the history command if you need to) Keep your lab PDF open. Keep your email and IRC open for support from the staff in case it is needed. Have MS Office or OpenOffice installed before starting and ensure you have an export to PDF feature. Be prepared to write a lot, be very precise and use screenshots to show output. You have 24h so take your time. SAVE YOUR WORK. Use screen to keep multiple SSH sessions open. Enumerate and work on one router at a time, no need to rush. Screenshot and document everything as much as you can to record your progress for the final report. (Keep your consoles open. don't kill the buffer) Afterthoughts WEP is pretty outdated but well documented and still very much pwnable. Maybe have the student attempt power changes as well to reach a "distant" AP. New attacks can be added to this, or a more "advanced wireless hacking" course can be setup. If not then just explained in updated documentation. (Default passwords, Pixie attack or wps bruteforce, Enterprise spoofing, etc.) Add one more router.