Be able to select the wireless control that eliminates a stated risk: WPA2-Enterprise with 802.1X for unique per-user authentication, and WIPS containment for rogue APs. The key is matching the mitigation to whether the problem is authentication, rogue devices, or management-frame abuse.
Start practicing
Wireless Network Security — choose a session length
Free · No account required
Domain overview
This GSEC domain covers securing 802. 11 wireless LANs: WPA2/WPA3 authentication choices, rogue AP and evil twin detection, WIPS containment, and management-frame attacks. Questions are scenario-based, asking you to pick the control or setting that best removes a specific risk rather than merely detecting it.
Exam objectives
Choosing WPA2-Enterprise with 802.1X/EAP over WPA2-Personal PSK to give each user unique credentials
Configuring WIPS rogue-AP classification and automatic containment of unauthorized access points
Identifying risky AP settings such as open authentication, WEP, or WPS enabled
Recognizing 802.11 deauthentication and disassociation frame floods as denial-of-service or handshake-capture attacks
Assuming a strong shared PSK is sufficient; WPA2-Personal still shares one key, so it cannot provide per-employee authentication or revocation
Confusing detection with prevention: a WIPS that only alerts does not contain a rogue AP unless containment is explicitly enabled
Treating deauthentication floods as encryption failures when they are unauthenticated management frames used to disrupt or capture handshakes
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator observes unauthorized devices connecting to an enterprise wireless network using WPA2-Personal. Which mitigation strategy best prevents credential sharing and ensures unique authentication for every employee?
2Refer to the exhibit. Which configuration setting poses the most significant risk to the wireless network environment?
3Which THREE of the following actions are considered best practices when hardening an enterprise wireless infrastructure?
4A security auditor notices that wireless clients are frequently disconnected by de-authentication frames that contain a spoofed MAC address of the access point. What is the auditor witnessing?
5Which TWO of the following statements are true regarding the use of WPA3 compared to WPA2?
6A security analyst at a financial firm is reviewing wireless traffic captured near the executive conference room. The capture shows a flood of 802.11 management frames with source addresses set to the company's legitimate AP MAC address, but the frames are not encrypted and are arriving at a high rate. Which type of attack is most likely occurring?
7A hospital's wireless network uses WPA2-Enterprise with PEAP-MSCHAPv2. A security engineer discovers that an attacker can capture a client's authentication exchange and crack the password offline. Which change most directly mitigates this specific attack?
8A security administrator is configuring a new wireless intrusion prevention system (WIPS) for a corporate campus. The administrator wants the WIPS to automatically contain an unauthorized access point that is broadcasting the corporate SSID. Which WIPS capability should be enabled to achieve this?
9A financial services firm deploys 802.1X with EAP-TLS on its corporate WLAN. During an assessment, a consultant captures the 802.11 four-way handshake and observes that the attacker cannot derive the PMK because the exchange never leaves the client and RADIUS-issued credentials exposed. Which property of EAP-TLS best explains why this capture alone cannot be used to impersonate a legitimate client?
10A hospital's wireless intrusion prevention system reports that a nearby attacker is broadcasting beacon frames that clone the SSID and BSSID of the hospital's legitimate access point at a higher signal strength, luring staff laptops to associate with the attacker's hardware. Which attack is being described, and which defense most directly addresses it?
11A security researcher is evaluating the susceptibility of a WPA3-Personal network to offline dictionary attacks. Which statement accurately describes the resistance provided by WPA3-SAE compared to WPA2-PSK?
12A retail chain wants to let customers join a guest WLAN without sharing the corporate preshared key, while still keeping guest traffic isolated from point-of-sale systems. Which design best meets these requirements?
13A security engineer is reviewing the WLAN configuration of a small business that uses WPA2-Personal. The owner wants to raise resistance to offline dictionary attacks against the preshared key without replacing all client hardware. Which two changes best accomplish this goal? (Choose two.)
14An assessor is standing in a parking lot outside a warehouse and needs to map the coverage footprint and identify all BSSIDs in range, including hidden networks, using a passive approach that does not associate to any AP. Which tool and technique fit this requirement?
Be able to select the wireless control that eliminates a stated risk: WPA2-Enterprise with 802.1X for unique per-user authentication, and WIPS containment for rogue APs. The key is matching the mitigation to whether the problem is authentication, rogue devices, or management-frame abuse.
The Courseiva GSEC question bank contains 14 questions in the Wireless Network Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Wireless Network Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included