SY0-301 · Question #172
After a recent breach, the security administrator performs a wireless survey of the corporate network. The security administrator notices a problem with the following output: MAC SSID ENCRYPTION…
The correct answer is A. Evil twin. An evil twin attack involves setting up a rogue access point that mimics a legitimate AP - using the same SSID, encryption type, and configuration - to trick users into connecting to the attacker's AP. In the output, all legitimate corporate APs share the OUI prefix 00:10:A1 (a…
Question
After a recent breach, the security administrator performs a wireless survey of the corporate network. The security administrator notices a problem with the following output:
MAC SSID ENCRYPTION POWER BEACONS 00:10:A1:36:12:CC MYCORP WPA2 CCMP 60 1202 00:10:A1:49:FC:37 MYCORP WPA2 CCMP 70 9102 FB:90:11:42:FA:99 MYCORP WPA2 CCMP 40 3031 00:10:A1:AA:BB:CC MYCORP WPA2 CCMP 55 2021 00:10:A1:FA:B1:07 MYCORP WPA2 CCMP 30 6044 Given that the corporate wireless network has been standardized, which of the following attacks is underway?
Options
- AEvil twin
- BIV attack
- CRogue AP
- DDDoS
How the community answered
(24 responses)- A75% (18)
- B17% (4)
- C4% (1)
- D4% (1)
Explanation
An evil twin attack involves setting up a rogue access point that mimics a legitimate AP - using the same SSID, encryption type, and configuration - to trick users into connecting to the attacker's AP. In the output, all legitimate corporate APs share the OUI prefix 00:10:A1 (a standardized hardware vendor prefix), but one AP (FB:90:11:42:FA:99) has a completely different MAC prefix while still broadcasting the 'MYCORP' SSID with WPA2 CCMP. This MAC anomaly is the hallmark of an evil twin. A rogue AP typically uses a different SSID. An IV attack targets WEP. A DDoS is a denial-of-service flood.
Topics
Community Discussion
No community discussion yet for this question.