115 questions, scenarios, and a course map for teaching 5G security
"If you can explain 5G-AKA to someone who's never seen it, draw the key hierarchy from memory, and name the misconfiguration behind a real incident — you know 5G security."
— THE BAR THIS CHAPTER SETS
This chapter turns the book into training material: a graded question bank (beginner → advanced → scenario → troubleshooting), a self-assessment, and trainer notes with course maps for one-, three-, and five-day formats. Use it to interview candidates, prepare for interviews, or build a 5G security course.
🎯 Learning objectives
Test 5G security knowledge across difficulty levels.
Work scenario and troubleshooting questions.
Self-assess with the knowledge radar.
Use the trainer course maps.
FIGURE 34.1Question Difficulty Map by Topic
Purpose: a map for building or grading interviews. Pick a topic row and the difficulty column appropriate to the role.
FIGURE 34.2The "Explain-It" Whiteboard Set — Draw These From Memory
Purpose: the five diagrams that separate someone who has read about 5G security from someone who understands it. Drawing them cold is the bar for an expert.
34.1 Beginner Questions (with answer cues)
💡 30 beginner questions
What does SUCI conceal, and why? (permanent identity; stop IMSI catching — Ch4)
What is mutual authentication? (both UE and network prove identity — Ch5)
Where is the long-term key K stored? (USIM and ARPF only — Ch3,7)
What does NEA0 mean? (null ciphering — Ch8)
What is the SEPP for? (roaming border security — Ch13)
What is the NRF's role? (NF directory + OAuth token authority — Ch3,10)
What is a 5G-GUTI? (temporary identity — Ch4,19)
What does the UPF do? (forwards user traffic; no keys — Ch3)
NSA vs SA in one line? (LTE-anchored vs full 5GC — Ch18)
What is NAS? (UE↔AMF signaling — Ch8)
What new protection did 5G add to the user plane? (integrity — Ch9)
What is mTLS? (both ends authenticate by cert — Ch10)
What is a network slice? (logical network on shared infra — Ch20)
What is an SNPN? (standalone private network — Ch21)
What is the AMF? (access/mobility + NAS security — Ch3)
What is AUTN? (network's proof token — Ch6)
Why is null SUCI scheme dangerous in production? (identity exposed — Ch4,25)
What is a false base station? (rogue cell — Ch1,24)
What does AKA stand for? (Authentication and Key Agreement — Ch5)
What is the home vs serving network? (subscription vs location — Ch1)
What is OAuth used for in SBA? (per-call authorization — Ch10)
What is K_SEAF? (the anchor key — Ch6,7)
What protects backhaul? (IPsec/NDS/IP — Ch14)
What is the NEF? (API exposure doorway — Ch12)
What is a handover? (connected cell change — Ch16)
What does the USIM hold? (K, AKA functions, home key — Ch3,4)
What is a KPI in security monitoring? (measurable indicator — Ch26)
What is the SOC? (Security Operations Center — Ch27)
Why do we audit? (verify protections are on — Ch28)
What is the biggest source of real breaches? (misconfiguration — Ch25)
34.2 Intermediate Questions
📘 30 intermediate questions
Walk the 5G-AKA message flow end to end. (Ch6)
How does ECIES conceal the SUPI? (Ch4)
Draw the key hierarchy from K to AS keys. (Ch7)
Explain the NAS SMC and replayed capabilities. (Ch8)
How does the SMF set UP security policy? (Ch9)
What do OAuth scope and audience claims do? (Ch10)
Compare TLS mode and PRINS on N32. (Ch13)
Explain NH/NCC at handover. (Ch16)
What is a mapped vs native security context? (Ch8,17)
How does NSSAA work? (Ch20)
What are the four slice isolation layers? (Ch20)
How does CMPv2 help at scale? (Ch10,14)
What does the AMF separation bit prevent? (Ch5,6)
Explain serving network name binding. (Ch5)
How does increased home control work? (Ch5,6)
Distinguish 5G-AKA and EAP-AKA′. (Ch5)
What does topology hiding do? (Ch13)
How is K_gNB derived and refreshed? (Ch7,16)
What is the authentication funnel? (Ch26)
How does the SEPP stop SS7-class attacks? (Ch13)
What is CAG in a PNI-NPN? (Ch21)
Explain UP integrity required vs preferred. (Ch9)
How does the NRF authorize discovery? (Ch10)
What is AKMA? (Ch5)
What changes for the edge UPF's N4/N9? (Ch22)
What is harvest-now-decrypt-later? (Ch32)
How does NWDAF support security? (Ch26,31)
What's the difference between authentication and authorization? (Ch1,10)
What is a signaling storm? (Ch23)
How does CU/DU split affect key placement? (Ch15)
34.3 Advanced Questions
🎯 25 advanced questions
Why does the serving network get HXRES* not XRES*, and what attack does it stop? (Ch6)
Explain horizontal vs vertical derivation and forward security. (Ch7,16)
How does ABBA defeat bidding-down, and where is it bound? (Ch7)
Why is a mapped context a security downgrade, item by item? (Ch17,18)
How does OAuth scope/audience contain SBA lateral movement? (Ch10,24)
What's the AKA linkability problem and its fix direction? (Ch6)
Why does "preferred" UP integrity fail open? (Ch9)
How would you detect a rogue gNB from telemetry? (Ch6,26,27)
Design a per-IE PRINS protection policy. (Ch13)
Where must K live in a cloud-native core, and why? (Ch11,29)
How do the four slice isolation layers fail independently? (Ch20)
What is crypto agility and why does it beat algorithm choice? (Ch32)
How does container escape reach the crown jewels? (Ch29)
Why is the NRF the SBA's single most critical NF? (Ch10,11)
Explain the SOC↔NOC handshake and a failure mode. (Ch27)
What's the difference between confidentiality and privacy in 5G? (Ch1,19)
Why does NSA security equal LTE security despite a 5G radio? (Ch18)
How do you prove (not assume) UP integrity is active? (Ch9,28)
What makes an audit evidence-based vs questionnaire-based? (Ch28)
How does the SN name break a network-relay attack? (Ch5)
Why is ML detection-only, and what are poisoning/evasion? (Ch31)
Design the monitoring to catch a stale-GUTI tracking attack. (Ch19,26)
How does the AUTS token resist SQN manipulation? (Ch6)
Map the top-5 risks of a national 5G network and their controls. (Ch24)
What's the highest-impact "zero trust" win in a typical 5G core? (Ch30)
Purpose: ready-made course structures. Map the book's parts and labs to a one-, three-, or five-day format depending on audience and depth.
FIGURE 34.5Knowledge Self-Assessment Radar
Purpose: find your gaps. Rate yourself per axis; the dents point to the chapters to revisit before an interview or an audit.
34.5 Trainer Teaching Notes
Lead with attacks, not specs. Every mechanism in this book exists because of an attack — teach the attack first, then the fix (the book's structure).
Use the labs early. The SUCI on/off lab (Ch33) converts skeptics in 20 minutes; show it Day 1.
Emphasize misconfiguration. Trainees will configure these networks — the Chapter-25 hotspots are the highest-value takeaway.
Make them draw. The key hierarchy (Ch7) and architecture (Ch3) must be reproducible from memory.
End with a capstone: build a threat model (Ch24) and run an audit (Ch28) on a lab network.
🧪 Mini exercise — mock interview
Pair up. One person picks five questions spanning beginner → advanced → scenario from this bank; the other answers, drawing where asked (key hierarchy, AKA flow). Score on accuracy, ability to reproduce diagrams from memory, and — for scenarios — whether they reach the root cause (usually a misconfiguration) not just a symptom. Swap. The candidate who can draw the key hierarchy cold and name the misconfiguration behind each scenario is the one who actually understands 5G security.