nerdexam
CompTIA

PT0-003 · Question #186

A company hires a penetration tester to test the security implementation of its wireless networks. The main goal for this assessment is to intercept and get access to sensitive data from the…

The correct answer is B. WiFi-Pumpkin. WiFi-Pumpkin for Wireless Interception WiFi-Pumpkin (B) is the correct choice because it is specifically designed to create rogue access points (evil twin attacks), allowing a penetration tester to intercept network traffic, capture credentials, and access sensitive data…

Submitted by kwame.gh· Mar 6, 2026Attacks and Exploits

Question

A company hires a penetration tester to test the security implementation of its wireless networks. The main goal for this assessment is to intercept and get access to sensitive data from the company's employees. Which of the following tools should the security professional use to best accomplish this task?

Options

  • AMetasploit
  • BWiFi-Pumpkin
  • CSET
  • DtheHarvester
  • EWiGLE.net

How the community answered

(48 responses)
  • A
    4% (2)
  • B
    83% (40)
  • C
    2% (1)
  • D
    2% (1)
  • E
    8% (4)

Explanation

WiFi-Pumpkin for Wireless Interception

WiFi-Pumpkin (B) is the correct choice because it is specifically designed to create rogue access points (evil twin attacks), allowing a penetration tester to intercept network traffic, capture credentials, and access sensitive data transmitted by employees who unknowingly connect to the fake wireless network.

Why the distractors are wrong:

  • Metasploit (A) is a powerful exploitation framework used for attacking systems and services, but it is not specifically designed for wireless interception or rogue AP attacks
  • SET (C) (Social Engineering Toolkit) focuses on social engineering attack vectors like phishing and spear-phishing, not wireless traffic interception
  • theHarvester (D) is an OSINT reconnaissance tool used to gather publicly available information like emails and domain data - not a wireless attack tool
  • WiGLE.net (E) is a wireless network mapping/geolocation database used to locate networks, not to intercept data

Memory Tip: Think of WiFi-Pumpkin as a "pumpkin trap" - just like a jack-o-lantern lures you in with its glow, it lures wireless victims to connect to a fake access point, capturing everything they send. If the question mentions wireless interception + sensitive data, think WiFi-Pumpkin.

Topics

#Wireless attacks#Rogue AP#Man-in-the-Middle (MITM)#Data interception

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice