GSEC Wireless Network Security Practice Question
A security auditor notices that wireless clients are frequently disconnected by de-authentication frames that contain a spoofed MAC address of the access point. What is the auditor witnessing?
⚠ Common exam trap
Students commonly mistake de-authentication attacks for Rogue AP installations or Evil Twin scenarios, confusing the initial disconnection phase with the subsequent credential capture phase.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A de-authentication Denial of Service (DoS) attack.
This behavior is characteristic of an 802.11 de-authentication attack. By sending spoofed management frames that appear to originate from the legitimate access point, an attacker can force clients to disconnect. This is often a precursor to forcing clients to reconnect to an attacker-controlled Evil Twin AP, enabling the interception of credentials or the execution of further man-in-the-middle attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A standard re-keying process defined by WPA2 standards.
Why it's wrong here
WPA2 re-keying happens periodically and is part of the normal operation of the protocol. It does not manifest as active, manual de-authentication of clients by spoofed MAC addresses, nor does it cause mass connectivity issues for users unless the key rotation process is severely misconfigured.
- ✓
A de-authentication Denial of Service (DoS) attack.
Why this is correct
De-authentication attacks exploit the lack of management frame integrity in older 802.11 standards. By spoofing the AP's address, the attacker forces clients to drop their connection. This is a common method for disrupting service or preparing a target for an Evil Twin or packet interception attack.
- ✗
An automated load balancing mechanism on the AP.
Why it's wrong here
Load balancing might cause an AP to suggest that clients connect to a different radio, but it would not involve spoofing MAC addresses or mass de-authentication of clients. This is an intentional administrative function, not a malicious action designed to disrupt client connectivity and intercept data.
- ✗
A probe response flood from an adjacent network.
Why it's wrong here
A probe response flood is a different type of wireless attack aimed at overwhelming client devices with network discovery information. It does not involve the de-authentication of already-connected clients, which is a distinct technique used to terminate existing sessions and force client re-authentication or roaming.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.