GAWN Exam Questions
85 real GAWN exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Wireless Network Attacks - Wi-Fi and Bluetooth
Which attack is MOST directly associated with WEP IV weaknesses?
WEPIV weaknessFMS attackkey recovery - Question #2Wireless Security Foundations and Reconnaissance
You find an SSID using WPA3-Personal but also advertising "transition mode". What does that imply?
WPA3transition modeSAEWPA2-PSK coexistence - Question #3Wireless Network Attacks - Wi-Fi and Bluetooth
A client associates to an evil twin AP with stronger signal and same SSID. Which client-side behavior MOST enables this?
evil twinRSSI preferenceauto-joinrogue AP - Question #4Wireless Security Foundations and Reconnaissance
Which management frames are protected by PMF when negotiated?
PMF802.11wdeauthenticationmanagement frame protection - Question #5Wireless Network Auditing and Defense
Which is the MOST effective audit recommendation to reduce credential theft risk in WPA2- Enterprise?
WPA2-EnterpriseRADIUScertificate validationcredential theft - Question #6Advanced Wireless Analysis and Exploitation
A capture shows EAPOL Message 2/4 includes SNonce and MIC. What does Message 2 primarily prove?
EAPOL4-way handshakePMKMIC - Question #7Wireless Network Auditing and Defense
Which control BEST mitigates WPS brute-force risk?
WPSPIN brute-forcevulnerabilitymitigation - Question #8Wireless Security Foundations and Reconnaissance
Which statement about GCMP is MOST accurate?
GCMPcipher suiteauthenticated encryptionWPA3 - Question #9Wireless Network Auditing and Defense
A wireless survey finds large areas at -80 dBm RSSI for the corporate SSID. From an auditor viewpoint, the MOST likely security risk is:
RSSIcoverage gapevil twinrogue AP - Question #10Wireless Security Foundations and Reconnaissance
Which device is the authoritative source for "who authenticated" in WPA2-Enterprise?
RADIUSWPA2-Enterpriseauthentication logging802.1X - Question #11Wireless Security Foundations and Reconnaissance
An auditor sees EAP method "EAP-MD5" enabled. What is the best classification?
EAP-MD5mutual authenticationcredential theftEAP methods - Question #12Wireless Network Auditing and Defense
Which wireless condition MOST impacts throughput due to contention, not PHY rate?
airtime utilizationCSMA/CAthroughputcontention - Question #13Wireless Network Auditing and Defense
What is the MOST direct mitigation for deauth attacks in legacy WPA2 networks?
deauthentication attackPMF802.11wDoS mitigation - Question #14Advanced Wireless Analysis and Exploitation
A capture shows RSN AKM 00-0f-ac:3. What does that indicate?
RSN IEAKM suite802.11rfast transition - Question #15Wireless Security Foundations and Reconnaissance
Which is MOST likely to leak a hidden SSID across the air repeatedly?
hidden SSIDprobe requestSSID disclosureclient probing - Question #16Wireless Network Attacks - Wi-Fi and Bluetooth
Which attack focuses on manipulating client behavior to join a network by answering probes broadly?
Karma attackprobe responseevil twinrogue AP - Question #17Wireless Network Auditing and Defense
A WPA2-Enterprise deployment uses VLAN assignment per user/group. Where is VLAN assignment MOST commonly enforced?
VLAN assignmentRADIUS attributesWPA2-Enterprisenetwork segmentation - Question #18Wireless Security Foundations and Reconnaissance
Which IEEE amendment is most associated with fast roaming improvements?
802.11rfast roamingBSS transitionIEEE amendment - Question #19Wireless Security Foundations and Reconnaissance
An auditor sees "Open" security but encrypted frames after association using OWE. What is the best description?
OWEopportunistic encryptionopen networkWPA3 - Question #20Wireless Network Auditing and Defense
Which audit evidence BEST supports a finding of "rogue AP" presence?
rogue APOUI detectionwired-side auditMAC address - Question #21Wireless Network Attacks - Wi-Fi and Bluetooth
Which is TRUE about Wi-Fi "transition mode" SSIDs (e.g., WPA2/WPA3)?
WPA3 transition modedowngrade attackmixed-mode SSIDprotocol negotiation - Question #22Wireless Security Foundations and Reconnaissance
An auditor sees EAPOL frames but no DHCP/ARP from the client. What phase is MOST likely underway?
EAPOL802.1X authenticationframe analysiskey establishment - Question #23Wireless Network Auditing and Defense
Which statement about WIPS vs WIDS is MOST accurate?
WIPSWIDSintrusion detectionwireless defense - Question #24Wireless Network Auditing and Defense
Which AP misconfiguration MOST increases risk of offline cracking?
PSK weaknessoffline crackingGTK rekeyAP misconfiguration - Question #25Wireless Security Foundations and Reconnaissance
A capture shows the client and AP both advertise PMF capable, but association proceeds without PMF. What is MOST likely?
PMFmanagement frame protectionRSN negotiationWPA3 - Question #26Wireless Security Foundations and Reconnaissance
In WPA2, which key encrypts broadcast/multicast traffic?
GTKWPA2 key hierarchybroadcast encryptionmulticast - Question #27Wireless Network Auditing and Defense
Which is the MOST accurate statement about "client isolation" (AP isolation)?
client isolationAP isolationLayer-2 segmentationWLAN security - Question #28Wireless Security Foundations and Reconnaissance
A Wireshark decode shows RSN Capabilities "Replay Counter: 16". What does that primarily relate to?
RSN capabilitiesreplay counteranti-replay protection802.11 security - Question #29Wireless Network Attacks - Wi-Fi and Bluetooth
Which is a common indicator of a "honeypot/evil twin" during assessment?
evil twinhoneypot APBSSID spoofingrogue access point - Question #30Wireless Network Auditing and Defense
A WPA2-Enterprise environment uses EAP-TLS. Which audit weakness is MOST critical?
EAP-TLScertificate revocation802.1X auditWPA2-Enterprise - Question #31Wireless Security Foundations and Reconnaissance
Which U.S. 2.4 GHz channel is NOT permitted for standard Wi-Fi client operation?
2.4 GHz channelschannel 14regulatory domainsFCC regulations - Question #32Wireless Security Foundations and Reconnaissance
Which metric BEST represents link quality relative to interference?
SNRRSSIRF signal qualityinterference measurement - Question #33Wireless Network Attacks - Wi-Fi and Bluetooth
Which attack is MOST directly associated with TKIP weaknesses (not AES)?
TKIPMichael MICWPA countermeasureslegacy encryption - Question #34Wireless Network Auditing and Defense
A wireless controller shows many authentication failures from unknown MACs across multiple APs. What audit concern is MOST plausible?
802.1X attackcredential stuffingauthentication failurewireless IDS - Question #35Wireless Security Foundations and Reconnaissance
Which 802.11 frame category includes RTS/CTS/ACK?
802.11 frame typescontrol framesRTS/CTSACK - Question #36Wireless Network Auditing and Defense
Which is the BEST practice for preventing users from connecting to rogue enterprise SSIDs?
rogue SSID preventionsupplicant configurationRADIUS certificate validationEAP method restriction - Question #37Wireless Network Auditing and Defense
An AP is configured for WPA2-Enterprise, but the client is prompted to "enter a password" instead of selecting a certificate. What is MOST likely?
EAP methodstunneled EAPWPA2-Enterprisepassword vs certificate - Question #38Wireless Network Attacks - Wi-Fi and Bluetooth
Which is a realistic limitation of relying solely on MAC filtering?
MAC filteringMAC spoofingaccess control bypassWLAN security - Question #39Wireless Network Attacks - Wi-Fi and Bluetooth
Which is MOST likely to be impacted by RF jamming?
RF jammingDoS attackWLAN availabilityinterference - Question #40Wireless Security Foundations and Reconnaissance
A site requires strong roaming for VoWiFi. Which standard is MOST relevant?
802.11rfast BSS transitionVoWiFiseamless roaming - Question #41Wireless Security Foundations and Reconnaissance
Which observed behavior is MOST consistent with a client performing directed probes for a hidden SSID?
directed probeshidden SSIDprobe requests802.11 frame types - Question #42Wireless Security Foundations and Reconnaissance
A capture includes Group Key Handshake frames. What does that MOST likely indicate?
GTK rotationgroup key handshakekey managementWPA2 - Question #43Wireless Security Foundations and Reconnaissance
Which is the MOST accurate statement about WPA3-SAE vs WPA2-PSK regarding offline guessing?
WPA3-SAEWPA2-PSKoffline dictionary attackkey exchange - Question #44Wireless Network Attacks - Wi-Fi and Bluetooth
Which attack uses forced disconnects to increase chance of capturing EAPOL handshakes?
deauthentication attackEAPOL handshakeframe injectionWPA cracking - Question #45Wireless Network Auditing and Defense
Which of the following is the MOST defensible "high severity" wireless finding in an enterprise?
WPA2-PSKshared credentialsenterprise riskaudit findings - Question #46Wireless Security Foundations and Reconnaissance
A capture shows 802.11 Authentication frames with algorithm "Open System". What does that indicate?
open system authentication802.11 auth frameslegacy authenticationWEP - Question #47Wireless Network Auditing and Defense
What is the MOST accurate audit statement about "hidden SSID + strong WPA2"?
hidden SSIDdirected probesSSID exposuresecurity controls - Question #48Wireless Security Foundations and Reconnaissance
Which item is MOST useful to differentiate multiple APs advertising the same SSID?
BSSIDESSIDAP identification802.11 addressing - Question #49Advanced Wireless Analysis and Exploitation
A WLAN uses 802.11r FT over-the-air. Which AKM suite commonly indicates this for PSK-based FT?
802.11r fast transitionAKM suiteRSN IEFT-PSK - Question #50Wireless Security Foundations and Reconnaissance
Which is the MOST accurate statement about "OWE transition mode"?
OWEtransition modeopportunistic wireless encryptionopen networks