Courseiva

GSEC Wireless Network Security Practice Question

Exhibit

AP-Config-Export: { 'ssid': 'Corp_Wifi', 'encryption': 'WPA2-PSK', 'wps_enabled': 'true', 'channel': '1', 'management_frame_protection': 'disabled' }

Refer to the exhibit. Which configuration setting poses the most significant risk to the wireless network environment?

⚠ Common exam trap

Candidates often confuse WPS vulnerabilities with standard WPA2 passphrase complexity issues, incorrectly assuming a strong pre-shared key mitigates an enabled Wi-Fi Protected Setup PIN flaw.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPS enabled allows for PIN-based brute-force attacks.

The exhibit shows WPS enabled on a WPA2-PSK network. WPS is notoriously vulnerable to brute-force attacks against its 8-digit PIN, which can be cracked in hours, revealing the underlying WPA2 passphrase. Disabling WPS is a standard security requirement because the protocol's design flaw allows for efficient recovery of the network key regardless of the passphrase's complexity, rendering the PSK security model entirely ineffective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Channel 1 selection is a performance concern.

    Why it's wrong here

    While Channel 1 might suffer from co-channel interference if other APs in the vicinity are using it, it is not a security vulnerability. Channel selection is a radio frequency management task that affects throughput and latency, not the cryptographic integrity of the wireless network connection.

  • ✓

    WPS enabled allows for PIN-based brute-force attacks.

    Why this is correct

    WPS (Wi-Fi Protected Setup) is highly insecure because the PIN validation process is flawed. Attackers can brute-force the PIN in small segments, eventually retrieving the network PSK. This vulnerability exists regardless of how strong the actual WPA2 password is, making it a critical security risk for any network.

  • ✗

    WPA2-PSK is insufficient for modern enterprise needs.

    Why it's wrong here

    While WPA2-PSK is less secure than WPA2-Enterprise, it is not the most significant risk in this specific configuration. The enabled WPS feature provides a direct, known exploit path to bypass the WPA2 encryption entirely, which is a much higher priority for immediate remediation than the PSK protocol.

  • ✗

    Management Frame Protection is disabled.

    Why it's wrong here

    Disabling MFP prevents protection against de-authentication attacks, which is a concern for availability. However, WPS is a more critical vulnerability because it leads to full network compromise and persistent credential theft, whereas MFP issues are limited to service disruption via denial-of-service attacks on the wireless client.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.