
GIAC Assessing and Auditing Wireless Networks
Domain 3Objective 2
Hotspots GAWN Practice Questions (Page 6)
Part of the Wireless Client and Network Attacks domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 3–4 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
6concepts
Questions 26–30
- 26
A company requires its traveling employees to use public Wi-Fi hotspots. The security team wants to ensure that all traffic is protected even if the hotspot is malicious. Which client-side control should be mandated as the primary defense?
Select an answer first - 27
A penetration tester is evaluating a public library's hotspot. The library uses a captive portal that redirects users to a login page. The tester notices that the captive portal's login page is served over HTTP and that after login, the user's session cookie is transmitted without encryption. Which attack is the tester most likely to successfully execute against a user who has just logged in?
Select an answer first - 28
A company's sales team frequently works from airport lounges and coffee shops. The IT department wants to provide a simple, consistent way for the sales team to securely access internal resources while on these public hotspots. The team uses a mix of Windows laptops and iOS devices. What is the most practical solution that provides consistent protection across all devices?
Select an answer first - 29
A security analyst is troubleshooting a report of a rogue access point on a corporate network. The analyst uses a wireless scanner and identifies an access point with the same SSID as the corporate network, but the BSSID is different. The analyst also notices that the rogue AP is broadcasting on a channel that is not used by the legitimate AP. What is the most effective way to determine if this is a malicious rogue AP or a misconfigured legitimate AP?
Select an answer first - 30
Which authentication method provides per-user credentials and is commonly used in enterprise environments to authenticate users against a RADIUS server?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GAWN” is a trademark of its owner, used for identification only.