Solution (source code)

= Solution

Take $S$ to contain every finite prime dividing $n$ and every prime of bad reduction of $E$. The local theory of <reduction of an elliptic curve> shows that Kummer classes of rational points are unramified outside $S$. Choose a basis of the constant group $E[n]\cong(\mathbb Z/n\mathbb Z)^2$. Kummer theory and the <Weil pairing> identify the resulting two scalar coordinates of
$$
E(K)/nE(K)\hookrightarrow H^1(K,E[n])
$$
with power classes in $K^*/(K^*)^n$. The ramification statement places both coordinates in $K(S,n)$. Restriction to $\Gamma$ is injective by the nondegeneracy proved in part b, and therefore
$$
|\Gamma|\leq|K(S,n)|^2.
$$