GAWN Exam Questions
85 real GAWN exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #51Wireless Network Auditing and Defense
An auditor sees that clients accept any server certificate during PEAP. Which mitigation is BEST?
PEAPcertificate validationEAP securityMDM profiles - Question #52Wireless Security Foundations and Reconnaissance
Which wireless security mechanism provides per-user accountability and centralized control?
WPA2-Enterprise802.1XRADIUSper-user authentication - Question #53Wireless Network Attacks - Wi-Fi and Bluetooth
Which is MOST likely to indicate a misconfigured "Enterprise" WLAN that is vulnerable to credential interception?
PEAPMSCHAPv2certificate validationcredential interception - Question #54Wireless Security Foundations and Reconnaissance
Which regulatory concept can force certain 5 GHz channels to be unavailable at times?
DFS5 GHz channelsregulatory complianceradar detection - Question #55Wireless Network Auditing and Defense
Which audit control BEST limits "over-the-air leakage" outside a building without changing encryption?
RF containmentpower tuningdirectional antennassignal leakage - Question #56Wireless Network Auditing and Defense
Which method is commonly used to audit the security of a hotspot?
hotspot securitytraffic monitoringwireless auditanomaly detection - Question #57Advanced Wireless Analysis and Exploitation
During an advanced fuzzing attack, what is the primary objective when targeting an 802.11 network?
fuzzing attack802.11 protocoldenial of serviceprotocol exploitation - Question #58Wireless Network Auditing and Defense
What are the recommended practices for securing WPA3-enabled networks? (Choose Three)
WPA3 securityWPSfirmware updateslegacy protocols - Question #59Other Wireless Technologies and Tools
In practical SDR applications, what is crucial for maintaining operational security while conducting wireless analyses?
SDRoperational securitywireless analysisphysical security - Question #60Advanced Wireless Analysis and Exploitation
A beacon advertises RSN AKM suites: 00-0f-ac:2 and 00-0f-ac:8. What is the MOST accurate description?
RSN IEAKM suite numbersbeacon analysisWPA2/WPA3 transition - Question #61Wireless Security Foundations and Reconnaissance
A client sends a Probe Request with SSID = "<broadcast>" (wildcard). What does that imply?
probe requestwildcard SSIDpassive scanning802.11 management frames - Question #62Wireless Security Foundations and Reconnaissance
An auditor sees repeated Deauthentication frames with Reason Code 7 in the air. Which is the BEST interpretation?
deauthentication framesreason codesmanagement frame analysis802.11 - Question #63Wireless Network Attacks - Wi-Fi and Bluetooth
Which artifact is REQUIRED to attempt a PMKID-based offline attack against WPA2-Personal?
PMKIDWPA2 offline attackRSNassociation frame - Question #64Advanced Wi-Fi Attacks and Mobile Device Exploitation
A WPA2-Enterprise SSID uses PEAP with MSCHAPv2 and "Do not validate server certificate" is common on endpoints. What is the highest-impact risk?
PEAP-MSCHAPv2evil twinrogue RADIUScertificate validation - Question #65Wireless Security Foundations and Reconnaissance
A beacon shows RSN pairwise cipher suites: CCMP and TKIP. What is the auditor's MOST defensible finding?
TKIPCCMPRSN cipher suitesWPA2 beacon - Question #66Wireless Network Auditing and Defense
PMF (802.11w) is set to "capable" but not "required". Which statement is TRUE?
PMF802.11wmanagement frame protectiondeauth spoofing - Question #67Wireless Security Foundations and Reconnaissance
Which frame type/subtype is MOST useful to identify the supported rates and channel of an AP without associating?
beacon framessupported ratespassive scanning802.11 management - Question #68Wireless Security Foundations and Reconnaissance
An AP operates on 5 GHz DFS channels. During assessment, the AP vacates the channel unexpectedly. What is the MOST likely trigger?
DFS5GHz channelsradar detectiondynamic channel switching - Question #69Wireless Security Foundations and Reconnaissance
You capture an Association Request showing RSN Capabilities "MFPR=0, MFPC=1". What does that mean?
RSN capabilitiesMFPCMFPR802.11w PMF - Question #70Wireless Network Auditing and Defense
Which wireless control BEST mitigates "evil twin" in WPA2-Enterprise when properly implemented?
evil twinRADIUS certificateWPA2-Enterpriseclient-side validation - Question #71Wireless Security Foundations and Reconnaissance
An auditor sees an SSID advertising OWE. What is the MOST accurate statement?
OWEopportunistic wireless encryptionopen networkunauthenticated encryption - Question #72Wireless Network Attacks - Wi-Fi and Bluetooth
Which of the following are vulnerabilities specific to WPA2 that are addressed in WPA3? (Choose Two)
WPA3KRACKdictionary attacksSAE - Question #73Other Wireless Technologies and Tools
In NFC transactions, what security mechanism is often employed to protect data integrity and confidentiality?
NFCsecure elementcontactless securitydata confidentiality - Question #74Other Wireless Technologies and Tools
What is the typical attack vector used to compromise high-frequency RFID systems?
RFIDeavesdroppingHF RFIDradio interception - Question #75Wireless Network Auditing and Defense
How can wireless client segmentation reduce security risks?
client segmentationnetwork isolationVLANwireless security architecture - Question #76Wireless Security Foundations and Reconnaissance
Which EAP method provides mutual authentication using client and server certificates?
EAP-TLSmutual authenticationcertificates802.1X - Question #77Wireless Security Foundations and Reconnaissance
A client repeatedly fails to connect; AP logs show "TKIP countermeasures invoked". What is the expected AP behavior?
TKIPMIC failurecountermeasuresWPA association blocking - Question #78Wireless Security Foundations and Reconnaissance
Which 2.4 GHz channel plan is MOST defensible for minimizing adjacent-channel interference in North America?
2.4GHz channelsnon-overlapping channelschannel planningRF interference - Question #79Wireless Security Foundations and Reconnaissance
You must discover hidden SSIDs with minimal active interaction. Which observed traffic will MOST reliably reveal the SSID?
hidden SSIDpassive reconnaissanceassociation requestSSID discovery - Question #80Wireless Network Attacks - Wi-Fi and Bluetooth
Which statement about WPA2-PSK offline cracking is TRUE?
WPA2-PSKoffline cracking4-way handshakePMKID - Question #81Wireless Security Foundations and Reconnaissance
A network uses 802.11r Fast Transition. Which artifact may reduce time needed for roaming?
802.11rFast TransitionPMK cachingroaming - Question #82Wireless Network Auditing and Defense
Which is the MOST accurate risk statement for "SSID hiding" as a security control?
SSID hidingprobe leakagesecurity controlsrisk assessment - Question #83Wireless Security Foundations and Reconnaissance
A wireless adapter must capture all management frames on a channel for assessment. Which mode is required?
monitor modemanagement framespacket capturewireless adapter - Question #84Wireless Network Attacks - Wi-Fi and Bluetooth
Which scenarios are indicative of a rogue network setup? (Choose Two)
rogue access pointevil twinSSID spoofingnetwork impersonation - Question #85Wireless Network Attacks - Wi-Fi and Bluetooth
What is a common vulnerability in Bluetooth technology that allows unauthorized access through brute force attacks?
BluebuggingBluetooth attacksunauthorized accessbrute force