
GIAC Assessing and Auditing Wireless Networks
Domain 5Objective 3
NFC GAWN Practice Questions (Page 2)
Part of the RFID and NFC Attacks domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 6–10
- 6
A security auditor is testing the compatibility of an NFC reader with various tag types. The reader is ISO/IEC 14443 compliant. Which tag types will the reader be able to communicate with?
Select an answer first - 7
A penetration tester is assessing the security of an NFC-based loyalty card system. The loyalty cards are Type 2 tags that store a numeric balance. The tester wants to perform a skimming attack to read the balance without the cardholder's knowledge. What is the most practical method?
Select an answer first - 8
A security analyst is reviewing the NFC implementation of a mobile payment app. The analyst is concerned that an attacker could place a malicious NFC reader near a user's phone and initiate a transaction without the user's knowledge. Which attack is the analyst concerned about?
Select an answer first - 9
Which NFC tag type is known for having the smallest memory capacity, typically between 96 and 2,048 bytes?
Select an answer first - 10
Which software tool is commonly used in NFC penetration testing to analyze and modify data on NFC tags?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GAWN” is a trademark of its owner, used for identification only.