Courseiva

GSEC Wireless Network Security Practice Question

A hospital's wireless intrusion prevention system reports that a nearby attacker is broadcasting beacon frames that clone the SSID and BSSID of the hospital's legitimate access point at a higher signal strength, luring staff laptops to associate with the attacker's hardware. Which attack is being described, and which defense most directly addresses it?

⚠ Common exam trap

The trap here is treating a rogue AP that merely broadcasts a matching SSID as harmless reconnaissance, when the cloned BSSID plus stronger signal is what drives client association.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An evil twin attack; requiring server certificate validation in the supplicant profile prevents clients from trusting the rogue AP.

Cloning an AP's SSID and BSSID with a stronger signal to attract clients is an evil twin attack. In an enterprise deployment the rogue cannot present a certificate signed by the trusted CA, so configuring the supplicant to validate the RADIUS server certificate causes the association to fail. Detection alone is weaker than preventing the trust decision.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A deauthentication flood; enabling Management Frame Protection forces the attacker's forged frames to be discarded by clients.

    Why it's wrong here

    A deauthentication flood spoofs management frames to disconnect clients, which is a different attack from cloning an AP's identity to attract associations. While 802.11w Management Frame Protection does defend against forged deauthentication and disassociation frames, it does not stop a client from voluntarily associating with a rogue AP that presents a matching SSID and BSSID.

  • ✗

    A MAC spoofing attack; deploying 802.1X with MAC authentication bypass on switch ports eliminates the rogue association.

    Why it's wrong here

    MAC spoofing involves impersonating a permitted client's hardware address and is not the mechanism described, since the attacker here impersonates the access point. MAC authentication bypass is a wired or wireless onboarding fallback that authenticates devices by their MAC address, which is easily spoofed. It does not validate the AP's identity, so it fails to prevent clients from joining the evil twin.

  • ✓

    An evil twin attack; requiring server certificate validation in the supplicant profile prevents clients from trusting the rogue AP.

    Why this is correct

    An evil twin impersonates a legitimate AP by cloning its SSID and BSSID, and a stronger signal persuades clients to associate. In WPA2/WPA3-Enterprise, the rogue cannot complete the TLS handshake without a certificate the client trusts, so enforcing server certificate validation in the supplicant stops the association. This directly defeats the impersonation rather than merely detecting it after the fact.

  • ✗

    A karma attack; disabling the SSID broadcast on legitimate APs prevents clients from probing for and joining the rogue device.

    Why it's wrong here

    A karma attack exploits clients that broadcast probe requests by responding to any SSID the client seeks, which differs from cloning one specific corporate BSSID. Hiding the SSID does not prevent the evil twin scenario because clients still send directed probes for known networks, and the rogue can answer them. Suppressing beacons can also break legitimate roaming and client onboarding.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.