GAWN Exam Questions
85 real GAWN exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #51
An auditor sees that clients accept any server certificate during PEAP. Which mitigation is BEST?
- Question #52
Which wireless security mechanism provides per-user accountability and centralized control?
- Question #53
Which is MOST likely to indicate a misconfigured "Enterprise" WLAN that is vulnerable to credential interception?
- Question #54
Which regulatory concept can force certain 5 GHz channels to be unavailable at times?
- Question #55
Which audit control BEST limits "over-the-air leakage" outside a building without changing encryption?
- Question #56
Which method is commonly used to audit the security of a hotspot?
- Question #57
During an advanced fuzzing attack, what is the primary objective when targeting an 802.11 network?
- Question #58
What are the recommended practices for securing WPA3-enabled networks? (Choose Three)
- Question #59
In practical SDR applications, what is crucial for maintaining operational security while conducting wireless analyses?
- Question #60
A beacon advertises RSN AKM suites: 00-0f-ac:2 and 00-0f-ac:8. What is the MOST accurate description?
- Question #61
A client sends a Probe Request with SSID = "<broadcast>" (wildcard). What does that imply?
- Question #62
An auditor sees repeated Deauthentication frames with Reason Code 7 in the air. Which is the BEST interpretation?
- Question #63
Which artifact is REQUIRED to attempt a PMKID-based offline attack against WPA2-Personal?
- Question #64
A WPA2-Enterprise SSID uses PEAP with MSCHAPv2 and "Do not validate server certificate" is common on endpoints. What is the highest-impact risk?
- Question #65
A beacon shows RSN pairwise cipher suites: CCMP and TKIP. What is the auditor's MOST defensible finding?
- Question #66
PMF (802.11w) is set to "capable" but not "required". Which statement is TRUE?
- Question #67
Which frame type/subtype is MOST useful to identify the supported rates and channel of an AP without associating?
- Question #68
An AP operates on 5 GHz DFS channels. During assessment, the AP vacates the channel unexpectedly. What is the MOST likely trigger?
- Question #69
You capture an Association Request showing RSN Capabilities "MFPR=0, MFPC=1". What does that mean?
- Question #70
Which wireless control BEST mitigates "evil twin" in WPA2-Enterprise when properly implemented?
- Question #71
An auditor sees an SSID advertising OWE. What is the MOST accurate statement?
- Question #72
Which of the following are vulnerabilities specific to WPA2 that are addressed in WPA3? (Choose Two)
- Question #73
In NFC transactions, what security mechanism is often employed to protect data integrity and confidentiality?
- Question #74
What is the typical attack vector used to compromise high-frequency RFID systems?
- Question #75
How can wireless client segmentation reduce security risks?
- Question #76
Which EAP method provides mutual authentication using client and server certificates?
- Question #77
A client repeatedly fails to connect; AP logs show "TKIP countermeasures invoked". What is the expected AP behavior?
- Question #78
Which 2.4 GHz channel plan is MOST defensible for minimizing adjacent-channel interference in North America?
- Question #79
You must discover hidden SSIDs with minimal active interaction. Which observed traffic will MOST reliably reveal the SSID?
- Question #80
Which statement about WPA2-PSK offline cracking is TRUE?
- Question #81
A network uses 802.11r Fast Transition. Which artifact may reduce time needed for roaming?
- Question #82
Which is the MOST accurate risk statement for "SSID hiding" as a security control?
- Question #83
A wireless adapter must capture all management frames on a channel for assessment. Which mode is required?
- Question #84
Which scenarios are indicative of a rogue network setup? (Choose Two)
- Question #85
What is a common vulnerability in Bluetooth technology that allows unauthorized access through brute force attacks?