Courseiva
Wireless Network Security →mediumMultiple Choice

GSEC Wireless Network Security Practice Question

A financial services firm deploys 802.1X with EAP-TLS on its corporate WLAN. During an assessment, a consultant captures the 802.11 four-way handshake and observes that the attacker cannot derive the PMK because the exchange never leaves the client and RADIUS-issued credentials exposed. Which property of EAP-TLS best explains why this capture alone cannot be used to impersonate a legitimate client?

⚠ Common exam trap

The trap here is assuming that capturing the four-way handshake always yields crackable key material, which only holds for password-derived methods like WPA2-Personal or PEAP-MSCHAPv2.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EAP-TLS performs mutual authentication using X.509 client and server certificates, so no reusable password-derived secret traverses the wireless medium.

EAP-TLS bases authentication on mutual X.509 certificate exchange, so neither a password nor a shared secret crosses the air. A captured four-way handshake yields only session-specific values that cannot be replayed or brute-forced into the PMK. Impersonation would require possession of the legitimate client's private key, which the passive capture does not provide.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    EAP-TLS encrypts the entire four-way handshake inside the TLS tunnel, so the ANonce and SNonce are never visible to a passive observer.

    Why it's wrong here

    The four-way handshake occurs after 802.1X/EAP authentication completes, and its EAPOL-Key frames travel unprotected at the link layer. The TLS tunnel protects only the EAP conversation inside 802.1X, not the subsequent key-exchange frames. Consequently a passive observer does see the ANonce and SNonce, but their visibility alone does not enable PMK recovery because no password-derived material is present.

  • ✓

    EAP-TLS performs mutual authentication using X.509 client and server certificates, so no reusable password-derived secret traverses the wireless medium.

    Why this is correct

    EAP-TLS authenticates both the supplicant and the authentication server with X.509 certificates and completes a TLS tunnel whose keys never expose a shared password. An attacker capturing the four-way handshake only obtains the ANonce, SNonce, and MIC values tied to that session, which cannot be replayed to derive the PMK for a new association, so impersonation fails without the client's private key.

  • ✗

    EAP-TLS relies on PEAP inner-method tunneling, which wraps the client credential exchange in a protected TLS channel so offline dictionary attacks are impossible.

    Why it's wrong here

    PEAP is a separate EAP method that uses a server certificate to build a TLS tunnel and then runs an inner method such as MSCHAPv2. EAP-TLS is itself the authentication method and does not require an inner method; it performs mutual certificate authentication directly. Confusing PEAP with EAP-TLS misidentifies the mechanism that protects credentials and misstates why the capture is useless to an attacker.

  • ✗

    EAP-TLS uses a per-session PSK that the RADIUS server generates and transmits to the client over the encrypted tunnel, so each session key is unique and unrecoverable from the capture.

    Why it's wrong here

    EAP-TLS does not distribute a PSK from the RADIUS server. Keying material is derived independently by both peers from the TLS master secret negotiated during the certificate-based handshake. Because no PSK is transmitted, the premise of a server-pushed session PSK is incorrect, and that misunderstanding would lead an assessor to look for a transmitted secret that does not exist in EAP-TLS deployments.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.