Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Assessing and Auditing Wireless Networks

Domain 5Objective 2

High-Frequency RFID Attacks GAWN Practice Questions (Page 1)

Part of the RFID and NFC Attacks domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
8concepts

Questions 1–5

  1. 1application · medium

    A museum uses HF RFID tags to track artifacts. The tags are placed on display cases, and readers at the exits detect unauthorized removal. A visitor discovers that they can use a smartphone to read the tag's data. The museum wants to prevent visitors from reading the tag data while still allowing the exit readers to function. Which control would be most effective?

    Select an answer first
  2. 2application · medium

    A hospital uses ISO 14443A-based access badges for staff entering medication storage rooms. A security auditor is concerned about an attacker using a low-cost NFC-enabled smartphone to capture badge data from a distance of 10–15 cm as staff walk through a corridor. Which control would most directly mitigate this specific threat without requiring badge replacement?

    Select an answer first
  3. 3application · medium

    A warehouse uses HF RFID readers to track inventory. An attacker uses a device to continuously transmit a signal at 13.56 MHz, preventing the readers from communicating with the tags. The warehouse manager wants to detect this attack quickly. Which of the following is the most effective detection method?

    Select an answer first
  4. 4application · medium

    A hospital uses HF RFID wristbands for patient identification. The wristband contains a tag that is read by staff using handheld readers. A security review identifies that the tag's memory is readable without authentication. Which of the following is the most significant risk introduced by this vulnerability?

    Select an answer first
  5. 5expert · medium

    A security team is evaluating an ISO 14443A access control system that uses the Crypto1 cipher. They have captured a large number of authentication traces. Which attack strategy is most likely to succeed in extracting the secret key?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GAWN” is a trademark of its owner, used for identification only.