nerdexam
CompTIA

220-1102 · Question #426

A remote user is experiencing issues connecting to a corporate email account on a laptop. The user clicks the internet connection icon and does not recognize the connected Wi-Fi. The help desk…

The correct answer is C. Instruct the user to disconnect the Wi-Fi. If a user is connected to an unrecognized Wi-Fi network suspected to be a rogue access point, the immediate first action is to disconnect to prevent potential compromise.

Security

Question

A remote user is experiencing issues connecting to a corporate email account on a laptop. The user clicks the internet connection icon and does not recognize the connected Wi-Fi. The help desk technician, who is troubleshooting the issue, assumes this is a rogue access point. Which of the following is the first action the technician should take?

Options

  • ARestart the wireless adapter.
  • BLaunch the browser to see if it redirects to an unknown site.
  • CInstruct the user to disconnect the Wi-Fi.
  • DInstruct the user to run the installed antivirus software.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    75% (21)
  • D
    14% (4)

Why each option

If a user is connected to an unrecognized Wi-Fi network suspected to be a rogue access point, the immediate first action is to disconnect to prevent potential compromise.

ARestart the wireless adapter.

Restarting the wireless adapter would likely reconnect the user to the same suspicious network, which is undesirable if it's a rogue access point.

BLaunch the browser to see if it redirects to an unknown site.

Launching a browser to check for redirects would involve interacting further with the potentially malicious network, increasing the risk of compromise instead of mitigating it.

CInstruct the user to disconnect the Wi-Fi.Correct

Disconnecting from an unrecognized Wi-Fi network immediately mitigates the risk of a rogue access point performing man-in-the-middle attacks, eavesdropping, or distributing malware, as part of the containment strategy in incident response. This action prevents further potential data exposure or compromise before any other investigative steps are taken.

DInstruct the user to run the installed antivirus software.

Running antivirus software is a good general security practice but does not prevent the ongoing risks associated with remaining connected to a rogue access point, and malware may not be immediately detected or prevented from exfiltrating data.

Concept tested: Rogue access point response

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#Rogue Access Point#Wi-Fi Security#Incident Response#Network Security Threats

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice