220-1102 · Question #173
A user connected a laptop to a wireless network and was tricked into providing log-in credentials for a website. Which of the following threats was used to carry out the attack?
The correct answer is D. Evil twin. The attack described, where a user connects to a fake wireless network and is tricked into providing credentials, is known as an evil twin attack.
Question
A user connected a laptop to a wireless network and was tricked into providing log-in credentials for a website. Which of the following threats was used to carry out the attack?
Options
- AZero day
- BVishing
- CDDoS
- DEvil twin
How the community answered
(45 responses)- A7% (3)
- B2% (1)
- C16% (7)
- D76% (34)
Why each option
The attack described, where a user connects to a fake wireless network and is tricked into providing credentials, is known as an evil twin attack.
A zero-day threat refers to a vulnerability that is unknown to the software vendor or public, for which no patch exists; it is not a type of attack that tricks users into providing credentials via Wi-Fi.
Vishing is a form of social engineering that uses voice communication (phone calls) to trick individuals into divulging sensitive information, not a wireless network attack.
DDoS (Distributed Denial of Service) is an attack that overwhelms a system, service, or network with a flood of traffic, making it unavailable to legitimate users, and does not involve tricking users into credential submission.
An evil twin attack involves a rogue access point disguised as a legitimate one, often using the same SSID. When a user connects to this fake access point, the attacker can intercept their network traffic, including login credentials submitted to websites, or direct them to malicious phishing sites.
Concept tested: Wireless network attack types-evil twin
Source: https://www.cisco.com/c/en/us/products/security/what-is-evil-twin.html
Topics
Community Discussion
No community discussion yet for this question.