220-1102 · Question #426
A remote user is experiencing issues connecting to a corporate email account on a laptop. The user clicks the internet connection icon and does not recognize the connected Wi-Fi. The help desk…
The correct answer is C. Instruct the user to disconnect the Wi-Fi. If a user is connected to an unrecognized Wi-Fi network suspected to be a rogue access point, the immediate first action is to disconnect to prevent potential compromise.
Question
A remote user is experiencing issues connecting to a corporate email account on a laptop. The user clicks the internet connection icon and does not recognize the connected Wi-Fi. The help desk technician, who is troubleshooting the issue, assumes this is a rogue access point. Which of the following is the first action the technician should take?
Options
- ARestart the wireless adapter.
- BLaunch the browser to see if it redirects to an unknown site.
- CInstruct the user to disconnect the Wi-Fi.
- DInstruct the user to run the installed antivirus software.
How the community answered
(28 responses)- A4% (1)
- B7% (2)
- C75% (21)
- D14% (4)
Why each option
If a user is connected to an unrecognized Wi-Fi network suspected to be a rogue access point, the immediate first action is to disconnect to prevent potential compromise.
Restarting the wireless adapter would likely reconnect the user to the same suspicious network, which is undesirable if it's a rogue access point.
Launching a browser to check for redirects would involve interacting further with the potentially malicious network, increasing the risk of compromise instead of mitigating it.
Disconnecting from an unrecognized Wi-Fi network immediately mitigates the risk of a rogue access point performing man-in-the-middle attacks, eavesdropping, or distributing malware, as part of the containment strategy in incident response. This action prevents further potential data exposure or compromise before any other investigative steps are taken.
Running antivirus software is a good general security practice but does not prevent the ongoing risks associated with remaining connected to a rogue access point, and malware may not be immediately detected or prevented from exfiltrating data.
Concept tested: Rogue access point response
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.