Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Assessing and Auditing Wireless Networks

Domain 5Objective 3

NFC GAWN Practice Questions (Page 8)

Part of the RFID and NFC Attacks domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
8concepts

Questions 36–38

  1. 36expert · hard

    A security researcher is investigating a reported vulnerability in an NFC-based payment system. The system uses card emulation mode and is based on ISO/IEC 14443. The researcher suspects that the system is vulnerable to eavesdropping because the communication is not encrypted. Which aspect of NFC makes eavesdropping particularly challenging, and how does it affect the attack?

    Select an answer first
  2. 37application · medium

    A penetration tester is assessing an NFC-based door lock system. The lock reads a static password from a Type 2 tag. The tester wants to perform a man-in-the-middle (MITM) attack to capture the password and replay it later. Which setup is required?

    Select an answer first
  3. 38expert · hard

    A company is implementing an NFC-based payment system that uses card emulation mode. The system must comply with PCI DSS requirements for protecting cardholder data. The security team is evaluating whether to use a secure element or host card emulation (HCE). Which consideration is most important for PCI DSS compliance?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GAWN

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GAWN” is a trademark of its owner, used for identification only.