nerdexam
EC-Council

212-82 · Question #125

A renowned research institute with a high-security wireless network recently encountered an advanced cyber attack. The attack was not detected by traditional security measures and resulted in…

The correct answer is B. Evil Twin Attack, where a rogue access point mimics a legitimate one to capture network traffic. Explanation An Evil Twin Attack (Option B) is the most logical choice because it operates passively and silently - a rogue access point mimics the legitimate network, tricking devices into connecting to it, allowing the attacker to intercept and exfiltrate data without…

Submitted by tom_us· Mar 6, 2026Cloud Security Risks & Threat Mitigation

Question

A renowned research institute with a high-security wireless network recently encountered an advanced cyber attack. The attack was not detected by traditional security measures and resulted in significant data exfiltration. The wireless network was equipped with WPA3 encryption, MAC address filtering, and had disabled SSID broadcasting. Intriguingly. the attack occurred without any noticeable disruption or changes in network performance. After an exhaustive forensic analysis, the cybersecurity team pinpointed the attack method. Which of the following wireless network-specific attacks was most likely used?

Options

  • AJamming Attack, disrupting network communications with interference signals
  • BEvil Twin Attack, where a rogue access point mimics a legitimate one to capture network traffic
  • CBluesnarfing. exploiting Bluetooth connections to access network data
  • DKRACK (Key Reinstallation Attack), exploiting vulnerabilities in the WPA2 protocol

How the community answered

(18 responses)
  • A
    11% (2)
  • B
    61% (11)
  • C
    22% (4)
  • D
    6% (1)

Explanation

Explanation

An Evil Twin Attack (Option B) is the most logical choice because it operates passively and silently - a rogue access point mimics the legitimate network, tricking devices into connecting to it, allowing the attacker to intercept and exfiltrate data without disrupting normal network performance or triggering traditional security alerts. Critically, this attack bypasses WPA3 encryption, MAC filtering, and hidden SSIDs because the attacker replicates the network's identity rather than breaking its defenses directly.

Why the distractors fail:

  • Option A (Jamming) is eliminated by the scenario itself - jamming disrupts network communications, which contradicts the clue that there was "no noticeable disruption."
  • Option C (Bluesnarfing) targets Bluetooth connections, not Wi-Fi networks, making it irrelevant to a wireless LAN security breach.
  • Option D (KRACK) exploits WPA2 specifically, but the network uses WPA3, which was designed to patch the vulnerabilities KRACK exploits.

Memory Tip

Think of the Evil Twin like an evil doppelgänger - it doesn't pick the lock (break encryption), it simply pretends to be the door itself. When an attack is described as silent, undetected, and data-focused, think impersonation, not brute force.

Topics

#Wireless Security#Evil Twin Attack#Network Threats#Data Exfiltration

Community Discussion

No community discussion yet for this question.

Full 212-82 Practice