Courseiva
Wireless Network Security →mediumMultiple Select

GSEC Wireless Network Security Practice Question

A security engineer is reviewing the WLAN configuration of a small business that uses WPA2-Personal. The owner wants to raise resistance to offline dictionary attacks against the preshared key without replacing all client hardware. Which two changes best accomplish this goal? (Choose two.)

⚠ Common exam trap

The trap here is assuming that hiding the SSID or enabling management frame protection prevents handshake capture, when neither changes the entropy of the preshared key or the offline attack model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Migrate the SSID to WPA3-SAE so the authentication exchange uses a simultaneous authentication of equals handshake resistant to offline guessing.

Offline dictionary attacks against WPA2-Personal succeed by deriving the PMK from a guessable passphrase and testing it against a captured handshake. Migrating to WPA3-SAE removes that offline attack path, and using a long random passphrase increases entropy so any captured material is impractical to crack. The two measures reinforce each other.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable 802.11w Management Frame Protection on the SSID to prevent capture of the four-way handshake.

    Why it's wrong here

    Management Frame Protection authenticates unicast management frames such as deauthentication and disassociation, protecting against forged disconnects. It does not encrypt or hide the four-way handshake, which consists of EAPOL-Key frames rather than management frames. An attacker who passively waits for a legitimate association can still capture the handshake, so 802.11w does not increase resistance to offline dictionary attacks.

  • ✗

    Disable the SSID broadcast and enable MAC address filtering to prevent attackers from capturing the handshake.

    Why it's wrong here

    Hiding the SSID and filtering MAC addresses are obscurity controls that do not affect handshake capture. Clients still transmit the SSID in probe requests, and MAC addresses are trivially spoofed. An attacker within radio range can capture the four-way handshake whenever any client associates, regardless of these settings, so neither measure increases the computational cost of an offline dictionary attack.

  • ✓

    Migrate the SSID to WPA3-SAE so the authentication exchange uses a simultaneous authentication of equals handshake resistant to offline guessing.

    Why this is correct

    WPA3-SAE replaces the PSK four-way handshake with a Dragonfly-based exchange that provides forward secrecy and resists passive offline dictionary attacks. An eavesdropper cannot capture a handshake and test candidate passphrases offline against it. This directly raises resistance to dictionary attacks, and WPA3-capable hardware can often be enabled through firmware or a controller profile update rather than a full replacement.

  • ✗

    Configure the AP to use TKIP instead of CCMP so that the captured handshake cannot be decrypted.

    Why it's wrong here

    TKIP is a deprecated cipher with known weaknesses and does not prevent handshake capture or offline PSK guessing. The attack targets the PMK derivation from the passphrase, which is independent of the pairwise cipher. Downgrading from CCMP to TKIP weakens the network, may break WPA3 compatibility, and does nothing to raise resistance to dictionary attacks against the preshared key.

  • ✓

    Replace the human-readable preshared key with a long, randomly generated passphrase of at least 20 characters stored in the client profile.

    Why this is correct

    Offline attacks succeed because the PSK is derived from a low-entropy passphrase. Substituting a long random string dramatically increases the search space, making brute-force recovery impractical even if a handshake is captured. This is a configuration-only change that works with existing WPA2 hardware and complements, rather than replaces, a later migration to SAE.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.