212-82 · Question #125
A renowned research institute with a high-security wireless network recently encountered an advanced cyber attack. The attack was not detected by traditional security measures and resulted in…
The correct answer is B. Evil Twin Attack, where a rogue access point mimics a legitimate one to capture network traffic. Explanation An Evil Twin Attack (Option B) is the most logical choice because it operates passively and silently - a rogue access point mimics the legitimate network, tricking devices into connecting to it, allowing the attacker to intercept and exfiltrate data without…
Question
A renowned research institute with a high-security wireless network recently encountered an advanced cyber attack. The attack was not detected by traditional security measures and resulted in significant data exfiltration. The wireless network was equipped with WPA3 encryption, MAC address filtering, and had disabled SSID broadcasting. Intriguingly. the attack occurred without any noticeable disruption or changes in network performance. After an exhaustive forensic analysis, the cybersecurity team pinpointed the attack method. Which of the following wireless network-specific attacks was most likely used?
Options
- AJamming Attack, disrupting network communications with interference signals
- BEvil Twin Attack, where a rogue access point mimics a legitimate one to capture network traffic
- CBluesnarfing. exploiting Bluetooth connections to access network data
- DKRACK (Key Reinstallation Attack), exploiting vulnerabilities in the WPA2 protocol
How the community answered
(18 responses)- A11% (2)
- B61% (11)
- C22% (4)
- D6% (1)
Explanation
Explanation
An Evil Twin Attack (Option B) is the most logical choice because it operates passively and silently - a rogue access point mimics the legitimate network, tricking devices into connecting to it, allowing the attacker to intercept and exfiltrate data without disrupting normal network performance or triggering traditional security alerts. Critically, this attack bypasses WPA3 encryption, MAC filtering, and hidden SSIDs because the attacker replicates the network's identity rather than breaking its defenses directly.
Why the distractors fail:
- Option A (Jamming) is eliminated by the scenario itself - jamming disrupts network communications, which contradicts the clue that there was "no noticeable disruption."
- Option C (Bluesnarfing) targets Bluetooth connections, not Wi-Fi networks, making it irrelevant to a wireless LAN security breach.
- Option D (KRACK) exploits WPA2 specifically, but the network uses WPA3, which was designed to patch the vulnerabilities KRACK exploits.
Memory Tip
Think of the Evil Twin like an evil doppelgänger - it doesn't pick the lock (break encryption), it simply pretends to be the door itself. When an attack is described as silent, undetected, and data-focused, think impersonation, not brute force.
Topics
Community Discussion
No community discussion yet for this question.