Courseiva

GSEC · topic practice

Wireless Network Security practice questions

This GSEC domain covers securing 802.11 wireless LANs: WPA2/WPA3 authentication choices, rogue AP and evil twin detection, WIPS containment, and management-frame attacks. Questions are scenario-based, asking you to pick the control or setting that best removes a specific risk rather than merely detecting it.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Wireless Network Security

What the exam tests

What to know about Wireless Network Security

Be able to select the wireless control that eliminates a stated risk: WPA2-Enterprise with 802.1X for unique per-user authentication, and WIPS containment for rogue APs. The key is matching the mitigation to whether the problem is authentication, rogue devices, or management-frame abuse.

Choosing WPA2-Enterprise with 802.1X/EAP over WPA2-Personal PSK to give each user unique credentials

Configuring WIPS rogue-AP classification and automatic containment of unauthorized access points

Identifying risky AP settings such as open authentication, WEP, or WPS enabled

Recognizing 802.11 deauthentication and disassociation frame floods as denial-of-service or handshake-capture attacks

Watch out for

Common Wireless Network Security exam traps

  • ▸Assuming a strong shared PSK is sufficient; WPA2-Personal still shares one key, so it cannot provide per-employee authentication or revocation
  • ▸Confusing detection with prevention: a WIPS that only alerts does not contain a rogue AP unless containment is explicitly enabled
  • ▸Treating deauthentication floods as encryption failures when they are unauthenticated management frames used to disrupt or capture handshakes

Practice set

Wireless Network Security questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full wireless explanation →

A security analyst is investigating a suspected rogue access point in the office. Which behavior most strongly indicates that a device is performing an Evil Twin attack?

Question 2mediummultiple choice
Read the full wireless explanation →

An organization requires a wireless security solution that prevents unauthorized personnel from connecting to the office Wi-Fi, even if the pre-shared key is leaked. Which technology should be implemented?

Question 3mediummultiple choice
Read the full wireless explanation →

Refer to the exhibit. What is the most likely risk associated with this log entry in an office environment?

Exhibit

Log_Entry: [2023-10-12 14:22:01] ALERT: Unauthorized AP detected on channel 6, SSID: 'Free_Public_Wifi', BSSID: 00:11:22:33:44:55
Question 4mediummultiple choice
Read the full wireless explanation →

A network administrator is configuring a new wireless LAN controller for a corporate office. The company requires that all wireless clients authenticate using individual credentials and that the credentials are never transmitted in cleartext over the air. The administrator also wants to ensure that session keys are unique per user and per session. Which authentication method should be implemented?

Question 5hardmulti select
Read the full wireless explanation →

A financial firm is deploying a new WPA3-Enterprise wireless network and wants to use 192-bit mode. Which TWO configuration requirements must be met to enable WPA3-Enterprise 192-bit mode? (Choose two.)

Question 6mediummultiple choice
Read the full wireless explanation →

A company is deploying a wireless network for guests. The security team wants to ensure that guest traffic is encrypted over the air and that guests cannot access internal corporate resources. Which combination of technologies should be implemented?

Question 7mediummultiple choice
Read the full wireless explanation →

A security engineer is hardening a corporate Wi-Fi deployment that uses WPA2-Enterprise with PEAP-MSCHAPv2 and a RADIUS server. The CIO wants to reduce the risk of over-the-air credential capture from malicious access points. Which server-side change best addresses this risk while keeping the existing client supplicant configuration unchanged?

Question 8mediummultiple choice
Read the full wireless explanation →

An administrator observes unauthorized devices connecting to an enterprise wireless network using WPA2-Personal. Which mitigation strategy best prevents credential sharing and ensures unique authentication for every employee?

Question 9hardmultiple choice
Read the full wireless explanation →

Refer to the exhibit. Which configuration setting poses the most significant risk to the wireless network environment?

Exhibit

AP-Config-Export: { 'ssid': 'Corp_Wifi', 'encryption': 'WPA2-PSK', 'wps_enabled': 'true', 'channel': '1', 'management_frame_protection': 'disabled' }
Question 10hardmulti select
Read the full wireless explanation →

Which THREE of the following actions are considered best practices when hardening an enterprise wireless infrastructure?

Question 11mediummultiple choice
Read the full wireless explanation →

A security auditor notices that wireless clients are frequently disconnected by de-authentication frames that contain a spoofed MAC address of the access point. What is the auditor witnessing?

Question 12hardmulti select
Read the full wireless explanation →

Which TWO of the following statements are true regarding the use of WPA3 compared to WPA2?

Question 13mediummultiple choice
Read the full wireless explanation →

A security analyst at a financial firm is reviewing wireless traffic captured near the executive conference room. The capture shows a flood of 802.11 management frames with source addresses set to the company's legitimate AP MAC address, but the frames are not encrypted and are arriving at a high rate. Which type of attack is most likely occurring?

Question 14mediummultiple choice
Read the full wireless explanation →

A hospital's wireless network uses WPA2-Enterprise with PEAP-MSCHAPv2. A security engineer discovers that an attacker can capture a client's authentication exchange and crack the password offline. Which change most directly mitigates this specific attack?

Question 15easymultiple choice
Read the full wireless explanation →

A security administrator is configuring a new wireless intrusion prevention system (WIPS) for a corporate campus. The administrator wants the WIPS to automatically contain an unauthorized access point that is broadcasting the corporate SSID. Which WIPS capability should be enabled to achieve this?

Question 16mediummultiple choice
Read the full wireless explanation →

A financial services firm deploys 802.1X with EAP-TLS on its corporate WLAN. During an assessment, a consultant captures the 802.11 four-way handshake and observes that the attacker cannot derive the PMK because the exchange never leaves the client and RADIUS-issued credentials exposed. Which property of EAP-TLS best explains why this capture alone cannot be used to impersonate a legitimate client?

Question 17hardmultiple choice
Read the full wireless explanation →

A hospital's wireless intrusion prevention system reports that a nearby attacker is broadcasting beacon frames that clone the SSID and BSSID of the hospital's legitimate access point at a higher signal strength, luring staff laptops to associate with the attacker's hardware. Which attack is being described, and which defense most directly addresses it?

Question 18hardmultiple choice
Read the full wireless explanation →

A security researcher is evaluating the susceptibility of a WPA3-Personal network to offline dictionary attacks. Which statement accurately describes the resistance provided by WPA3-SAE compared to WPA2-PSK?

Question 19easymultiple choice
Read the full wireless explanation →

A retail chain wants to let customers join a guest WLAN without sharing the corporate preshared key, while still keeping guest traffic isolated from point-of-sale systems. Which design best meets these requirements?

Question 20mediummulti select
Read the full wireless explanation →

A security engineer is reviewing the WLAN configuration of a small business that uses WPA2-Personal. The owner wants to raise resistance to offline dictionary attacks against the preshared key without replacing all client hardware. Which two changes best accomplish this goal? (Choose two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Wireless Network Security sessions

Start a Wireless Network Security only practice session

Every question in these sessions is drawn from the Wireless Network Security domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Wireless Network Security?
Be able to select the wireless control that eliminates a stated risk: WPA2-Enterprise with 802.1X for unique per-user authentication, and WIPS containment for rogue APs. The key is matching the mitigation to whether the problem is authentication, rogue devices, or management-frame abuse.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Wireless Network Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Wireless Network Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.