nerdexam
GIAC

GSEC · Question #139

An employee attempting to use your wireless portal reports receiving the error shown below. Which scenario is occurring?

The correct answer is D. Another access point is attempting to intercept the data. A security or certificate warning on a wireless captive portal typically signals an evil twin rogue access point presenting an invalid certificate while attempting to intercept traffic.

Network Security

Question

An employee attempting to use your wireless portal reports receiving the error shown below. Which scenario is occurring?

Exhibit

GSEC question #139 exhibit

Options

  • AA denial-of-service attack is preventing a response from the portal.
  • BAnother access point is deauthenticating legitimate clients.
  • CThe encrypted data is being intercepted and decrypted.
  • DAnother access point is attempting to intercept the data.

How the community answered

(46 responses)
  • A
    11% (5)
  • B
    2% (1)
  • C
    7% (3)
  • D
    80% (37)

Why each option

A security or certificate warning on a wireless captive portal typically signals an evil twin rogue access point presenting an invalid certificate while attempting to intercept traffic.

AA denial-of-service attack is preventing a response from the portal.

A denial-of-service attack would block all responses entirely rather than allow a client to reach a portal and receive a specific error message.

BAnother access point is deauthenticating legitimate clients.

A deauthentication attack forcibly disconnects clients from the network at the 802.11 layer and would not produce a portal-level error visible in a browser.

CThe encrypted data is being intercepted and decrypted.

Passive interception and offline decryption of already-captured encrypted data occurs silently and does not cause the client to receive a real-time visible error during the connection attempt.

DAnother access point is attempting to intercept the data.Correct

An evil twin attack involves a rogue access point mimicking a legitimate one to position itself as a man-in-the-middle; when a client connects and reaches the HTTPS portal, the rogue AP cannot present the legitimate SSL certificate, triggering a certificate mismatch or trust error in the browser. This specific portal-level error is a direct indicator of a rogue AP interception attempt rather than a passive or volumetric attack.

Concept tested: Evil twin rogue AP certificate warning identification

Source: https://learn.microsoft.com/en-us/windows/security/operating-system-security/network-security/wifi/wireless-security-scenarios

Topics

#evil twin#rogue access point#wireless interception#MITM

Community Discussion

No community discussion yet for this question.

Full GSEC Practice