nerdexam
GIAC

GPEN · Question #47

Which of the following can be used to mitigate the evil twin phishing attack?

The correct answer is D. IPSec VPN. An IPSec VPN encrypts all traffic end-to-end, so even if a user connects to a rogue evil twin access point, intercepted data remains unreadable to the attacker.

Exploitation & Post-Exploitation Techniques

Question

Which of the following can be used to mitigate the evil twin phishing attack?

Options

  • ASARA
  • BObiwan
  • CMagic Lantern
  • DIPSec VPN

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    13% (5)
  • D
    79% (30)

Why each option

An IPSec VPN encrypts all traffic end-to-end, so even if a user connects to a rogue evil twin access point, intercepted data remains unreadable to the attacker.

ASARA

SARA (Security Auditor's Research Assistant) is a network vulnerability scanning tool used for auditing, not a countermeasure against rogue access points.

BObiwan

Obiwan is a network monitoring tool, not a defense mechanism against evil twin phishing attacks.

CMagic Lantern

Magic Lantern is an FBI keystroke-logging tool used for law enforcement surveillance and is unrelated to wireless attack mitigation.

DIPSec VPNCorrect

An evil twin attack sets up a rogue wireless access point mimicking a legitimate one to perform a man-in-the-middle interception of client traffic. Using an IPSec VPN ensures all transmitted data is encrypted and authenticated at the network layer, rendering intercepted packets unintelligible to the attacker and preventing credential or session theft regardless of which AP the client connects through.

Concept tested: Mitigating evil twin rogue AP attack with VPN encryption

Source: https://www.cisa.gov/sites/default/files/publications/aa21-265a-avoiding-the-temptation-of-evil-twin-networks.pdf

Topics

#evil twin attack#wireless phishing#IPSec VPN#wireless countermeasures

Community Discussion

No community discussion yet for this question.

Full GPEN Practice