GSEC Wireless Network Security Practice Question
A hospital's wireless network uses WPA2-Enterprise with PEAP-MSCHAPv2. A security engineer discovers that an attacker can capture a client's authentication exchange and crack the password offline. Which change most directly mitigates this specific attack?
⚠ Common exam trap
The trap here is assuming that enabling Protected Management Frames or 802.11w hardens the authentication exchange, when it only protects management frames and leaves the crackable MSCHAPv2 handshake untouched.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure EAP-TLS with client certificates for all wireless clients.
PEAP-MSCHAPv2 transmits an MSCHAPv2 challenge-response that can be captured and cracked offline because the protocol's DES-based keying is weak and lacks channel binding. Replacing it with EAP-TLS removes the password-derived secret entirely, requiring client certificates for mutual authentication. PMF, 802.11w, and PSK length changes do not alter the inner EAP method, so they leave the offline cracking vulnerability intact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy Protected Management Frames (PMF) on all access points.
Why it's wrong here
PMF protects management frames such as deauthentication and disassociation from spoofing, but it does not alter the inner authentication exchange of PEAP-MSCHAPv2. The attack described captures the MSCHAPv2 challenge-response and cracks it offline because the protocol uses weak DES-based keying and no channel binding. Enabling PMF would not prevent that capture or the offline cracking, so it fails to address the root cause.
- ✗
Enable 802.11w on the wireless controller.
Why it's wrong here
802.11w is the IEEE standard for Protected Management Frames, and it secures unicast and broadcast management frames. It does not change the EAP method or the MSCHAPv2 exchange, so an attacker can still capture the authentication handshake and crack it offline. While 802.11w is a good hardening measure, it does not mitigate the specific credential-cracking attack described.
- ✓
Configure EAP-TLS with client certificates for all wireless clients.
Why this is correct
PEAP-MSCHAPv2 is vulnerable to offline dictionary attacks because the captured MSCHAPv2 exchange can be cracked without further interaction. EAP-TLS replaces password-based inner authentication with mutual certificate authentication, so there is no crackable password hash. This directly eliminates the attack vector while preserving WPA2-Enterprise. It is the most targeted mitigation for the described offline cracking scenario.
- ✗
Increase the WPA2 pre-shared key length to 64 characters.
Why it's wrong here
WPA2-Enterprise does not use a pre-shared key; it relies on 802.1X/EAP authentication. Changing a PSK length has no effect on an enterprise deployment. The attack targets the PEAP-MSCHAPv2 inner authentication, not a PSK. This option confuses Personal and Enterprise modes and therefore cannot mitigate the offline cracking of MSCHAPv2.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.