N10-005 · Question #771
Ann, a user, connects to her company's secured wireless network in the conference room when attending meetings. While using the conference room this morning, Ann notices an unsecured wireless…
The correct answer is D. Evil twin. An evil twin attack involves setting up a fraudulent wireless access point with the same SSID as a legitimate network to lure users into connecting to it.
Question
Ann, a user, connects to her company's secured wireless network in the conference room when attending meetings. While using the conference room this morning, Ann notices an unsecured wireless network with the same name is available. Ann connects her laptop to this network instead of to the secured one. Ann has fallen victim to which of the following threats?
Options
- ARogue access point
- BARP poisoning
- CReplay attack
- DEvil twin
How the community answered
(40 responses)- A5% (2)
- B3% (1)
- C3% (1)
- D90% (36)
Why each option
An evil twin attack involves setting up a fraudulent wireless access point with the same SSID as a legitimate network to lure users into connecting to it.
A rogue access point is an unauthorized AP added to a network without admin approval, but it does not necessarily mimic an existing SSID - the defining characteristic here is the SSID duplication.
ARP poisoning is a Layer 2 attack where an attacker sends forged ARP replies to associate their MAC address with a legitimate IP, which is unrelated to wireless SSID spoofing.
A replay attack involves capturing and retransmitting valid authentication credentials or packets to gain unauthorized access, which is not what is described in this scenario.
An evil twin is a malicious access point configured with the same SSID (and often the same BSSID appearance) as a trusted network, designed to deceive users into connecting. Because Ann's laptop connected to an unsecured network bearing her company's exact network name, an attacker is impersonating the legitimate AP. Once connected, the attacker can intercept all of Ann's unencrypted traffic.
Concept tested: Evil twin wireless attack SSID spoofing
Source: https://www.cisco.com/c/en/us/products/security/what-is-an-evil-twin-attack.html
Topics
Community Discussion
No community discussion yet for this question.