nerdexam
CompTIA

N10-005 · Question #771

Ann, a user, connects to her company's secured wireless network in the conference room when attending meetings. While using the conference room this morning, Ann notices an unsecured wireless…

The correct answer is D. Evil twin. An evil twin attack involves setting up a fraudulent wireless access point with the same SSID as a legitimate network to lure users into connecting to it.

Network security

Question

Ann, a user, connects to her company's secured wireless network in the conference room when attending meetings. While using the conference room this morning, Ann notices an unsecured wireless network with the same name is available. Ann connects her laptop to this network instead of to the secured one. Ann has fallen victim to which of the following threats?

Options

  • ARogue access point
  • BARP poisoning
  • CReplay attack
  • DEvil twin

How the community answered

(40 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    3% (1)
  • D
    90% (36)

Why each option

An evil twin attack involves setting up a fraudulent wireless access point with the same SSID as a legitimate network to lure users into connecting to it.

ARogue access point

A rogue access point is an unauthorized AP added to a network without admin approval, but it does not necessarily mimic an existing SSID - the defining characteristic here is the SSID duplication.

BARP poisoning

ARP poisoning is a Layer 2 attack where an attacker sends forged ARP replies to associate their MAC address with a legitimate IP, which is unrelated to wireless SSID spoofing.

CReplay attack

A replay attack involves capturing and retransmitting valid authentication credentials or packets to gain unauthorized access, which is not what is described in this scenario.

DEvil twinCorrect

An evil twin is a malicious access point configured with the same SSID (and often the same BSSID appearance) as a trusted network, designed to deceive users into connecting. Because Ann's laptop connected to an unsecured network bearing her company's exact network name, an attacker is impersonating the legitimate AP. Once connected, the attacker can intercept all of Ann's unencrypted traffic.

Concept tested: Evil twin wireless attack SSID spoofing

Source: https://www.cisco.com/c/en/us/products/security/what-is-an-evil-twin-attack.html

Topics

#evil twin#wireless security#SSID spoofing#rogue access point

Community Discussion

No community discussion yet for this question.

Full N10-005 Practice