nerdexam
EC-Council

312-50V11 · Question #1031

An attacker utilizes a Wi-Fi Pineapple to run an access point with a legitimate-looking SSID for a nearby business in order to capture the wireless password. What kind of attack is this?

The correct answer is B. Evil-twin attack. An evil-twin attack involves deploying a rogue wireless access point that broadcasts the same SSID as a legitimate network to trick clients into connecting and surrendering credentials.

Hacking Wireless Networks

Question

An attacker utilizes a Wi-Fi Pineapple to run an access point with a legitimate-looking SSID for a nearby business in order to capture the wireless password. What kind of attack is this?

Options

  • AMAC spoofing attack
  • BEvil-twin attack
  • CWar driving attack
  • DPhishing attack

How the community answered

(16 responses)
  • A
    6% (1)
  • B
    94% (15)

Why each option

An evil-twin attack involves deploying a rogue wireless access point that broadcasts the same SSID as a legitimate network to trick clients into connecting and surrendering credentials.

AMAC spoofing attack

A MAC spoofing attack involves changing a device's MAC address to impersonate another device on the network, which does not require setting up a rogue access point with a cloned SSID.

BEvil-twin attackCorrect

An evil-twin attack uses a rogue AP - often a device like the Wi-Fi Pineapple - broadcasting a legitimate-looking SSID to lure nearby clients into associating with it instead of the real AP. Once connected, the attacker can capture the WPA handshake or serve a captive portal to harvest the wireless password through a man-in-the-middle position.

CWar driving attack

War driving is the act of physically traveling through an area while scanning for available wireless networks, not deploying a rogue AP to capture credentials.

DPhishing attack

A phishing attack uses deceptive emails, messages, or websites to trick users into revealing credentials, and does not involve impersonating a wireless access point.

Concept tested: Evil-twin rogue access point credential capture attack

Source: https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Mobility/RogueAP/Cisco_Rogue_AP_Solution.html

Topics

#evil twin attack#Wi-Fi Pineapple#rogue access point#SSID spoofing

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice