nerdexam
CompTIA

PT0-003 · Question #76

During a security assessment, a penetration tester needs to exploit a vulnerability in a wireless network's authentication mechanism to gain unauthorized access to the network. Which of the…

The correct answer is A. KARMA attack. A KARMA attack exploits the behavior of wireless devices that automatically probe for previously connected Wi-Fi networks by broadcasting their preferred network list (PNL) without authentication. The attacker sets up a rogue access point that dynamically responds to these…

Submitted by emma.c· Mar 6, 2026Attacks and Exploits

Question

During a security assessment, a penetration tester needs to exploit a vulnerability in a wireless network's authentication mechanism to gain unauthorized access to the network. Which of the following attacks would the tester most likely perform to gain access?

Options

  • AKARMA attack
  • BBeacon flooding
  • CMAC address spoofing
  • DEavesdropping

How the community answered

(24 responses)
  • A
    79% (19)
  • B
    8% (2)
  • C
    4% (1)
  • D
    8% (2)

Explanation

A KARMA attack exploits the behavior of wireless devices that automatically probe for previously connected Wi-Fi networks by broadcasting their preferred network list (PNL) without authentication. The attacker sets up a rogue access point that dynamically responds to these probe requests by impersonating any SSID the client device is searching for, effectively tricking the device into connecting to the malicious network without user intervention. This allows the attacker to bypass authentication mechanisms and gain unauthorized access, often positioning themselves as a man-in-the-middle (MITM) to intercept data or further exploit the victim.

Topics

#wireless attacks#KARMA attack#authentication bypass

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice