Courseiva

GSEC Wireless Network Security Practice Question

A retail chain wants to let customers join a guest WLAN without sharing the corporate preshared key, while still keeping guest traffic isolated from point-of-sale systems. Which design best meets these requirements?

⚠ Common exam trap

The trap here is believing that hiding the SSID or rotating a guest passphrase provides isolation, when only VLAN segmentation and firewall policy actually separate guest traffic from internal systems.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a separate guest SSID mapped to a dedicated VLAN with client isolation enabled and no route to internal subnets.

Guest access is best delivered on its own SSID mapped to a segmented VLAN with client isolation and no internal routing. This keeps the corporate preshared key private, prevents guest-to-guest and guest-to-internal access, and protects point-of-sale systems through network segmentation rather than relying on the guest credential.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Broadcast the corporate SSID with WPA3-SAE and give customers a rotating guest passphrase that changes weekly.

    Why it's wrong here

    Sharing a rotating passphrase still exposes a credential that guests can retain or share, and SAE passphrases on the corporate SSID place guests on the same logical network as internal devices unless further segmentation exists. The requirement to avoid sharing the corporate preshared key is only partially met, and isolation from point-of-sale systems is not guaranteed by the passphrase rotation alone.

  • ✗

    Deploy the guest network on the same SSID as corporate users and rely on 802.1X to assign guests a restricted role after authentication.

    Why it's wrong here

    Customers generally lack the credentials needed for 802.1X, so this design blocks the guest use case. Placing guests and corporate devices on one SSID also increases the chance of misconfiguration that grants broader access than intended. While dynamic authorization can assign roles, requiring enterprise authentication for retail guests is operationally impractical and does not meet the stated requirement.

  • ✗

    Enable a hidden guest SSID using WEP with a shared key so customers can connect without configuration changes.

    Why it's wrong here

    WEP is cryptographically broken and trivially cracked, so it provides no meaningful protection. Hiding the SSID offers no security benefit because the SSID is still discoverable in probe and association frames. This option also does nothing to isolate guest traffic from point-of-sale systems, and it would expose customer traffic to interception, making it unsuitable for any production guest network.

  • ✓

    Configure a separate guest SSID mapped to a dedicated VLAN with client isolation enabled and no route to internal subnets.

    Why this is correct

    A distinct guest SSID bound to its own VLAN keeps guest traffic on a segmented broadcast domain, and client isolation prevents guests from reaching each other. With no routing or ACL permitting access to internal subnets, point-of-sale systems stay unreachable. This satisfies open or captive-portal guest access without distributing the corporate preshared key, which remains protected for internal users.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.