
GIAC Assessing and Auditing Wireless Networks
Domain 2Objective 1
Attacking Weak Encryption GAWN Practice Questions (Page 8)
Part of the Wireless Encryption and Authentication domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 4–6 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 36–40
- 36
What must be captured to perform an offline dictionary attack against a WPA/WPA2 PSK?
Select an answer first - 37
A penetration tester is assessing a WPA2-PSK network. The tester has captured a handshake but does not have a wordlist. Which approach is most appropriate to attempt to recover the passphrase?
Select an answer first - 38
You are testing a network that uses WPA-TKIP. You want to demonstrate the risk of TKIP by performing a packet injection attack. Which tool is commonly used to inject packets into a wireless network?
Select an answer first - 39
Which attack method is used to recover a WPA/WPA2 PSK from a captured handshake?
Select an answer first - 40
A security analyst is examining a wireless capture and sees that the AP is broadcasting a beacon with the encryption field set to 'WEP'. The analyst also notices that some clients are using WPA2. Which conclusion is most accurate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GAWN” is a trademark of its owner, used for identification only.