Courseiva
Pen Test Planning →mediumMultiple Choice

GPEN Pen Test Planning Practice Question

You are planning a penetration test for a client with a large wireless network. The client wants to assess the security of their WPA3-Enterprise deployment. Which of the following should be included in the Rules of Engagement to address the risk of disrupting legitimate wireless users?

⚠ Common exam trap

The trap here is thinking that passive scanning is sufficient for a thorough wireless penetration test, when active attacks are often needed to validate WPA3-Enterprise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A schedule for testing during off-peak hours and a maximum number of deauthentication frames to send per minute.

The most appropriate inclusion is a schedule for off-peak testing and a limit on deauthentication frames. This minimizes the number of users affected and prevents network instability. It directly mitigates the risk of disrupting legitimate wireless users while still allowing active testing of WPA3-Enterprise security. Other options either do not sufficiently reduce risk or limit testing effectiveness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A schedule for testing during off-peak hours and a maximum number of deauthentication frames to send per minute.

    Why this is correct

    Off-peak testing reduces the number of users affected, and limiting deauthentication frames prevents overwhelming the network and causing widespread disconnections. This directly addresses the risk of disrupting legitimate wireless users. It is a specific, measurable control that can be included in the Rules of Engagement. This approach balances the need to test wireless security with the need to maintain network availability.

  • ✗

    A requirement to use only passive wireless scanning techniques and avoid any active attacks.

    Why it's wrong here

    Passive scanning alone may not adequately test the security of WPA3-Enterprise, as it cannot validate authentication and encryption weaknesses that require active attacks. While passive scanning minimizes disruption, it may not meet the client's objective to assess security thoroughly. The question asks to address the risk of disruption while still conducting a meaningful test, so a combination of active testing with controls is more appropriate.

  • ✗

    A requirement to perform all wireless testing only during business hours to blend in with normal traffic.

    Why it's wrong here

    Testing during business hours increases the risk of disrupting legitimate users because the network is heavily utilized. It also makes it harder to distinguish testing traffic from normal traffic, potentially causing interference. The goal is to minimize disruption, so scheduling during off-peak hours is generally safer. Testing during business hours does not address the risk and may actually exacerbate it.

  • ✗

    A predefined list of authorized MAC addresses for testing devices to prevent accidental disconnections.

    Why it's wrong here

    Authorized MAC addresses can help avoid interference with specific devices, but they do not address the broader risk of disrupting legitimate users. An attacker could still spoof MAC addresses, and the list does not prevent testing activities like deauthentication attacks from affecting other clients. It is a partial measure but not the most comprehensive way to manage disruption risk in the RoE.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.