CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium

A user connects to a Wi-Fi network named 'Airport_Free_WiFi' that appears identical to the legitimate airport network but has a slightly stronger signal. After connecting, the user's traffic is intercepted. Which attack has most likely occurred?

  1. ADNS poisoning
  2. BBluejacking
  3. CEvil twin attack
  4. DMAC flooding
Show answer & explanation

Correct answer: C. Evil twin attack

An evil twin attack involves setting up a rogue access point with the same or similar SSID as a legitimate network to lure users into connecting, allowing the attacker to intercept traffic.

Why the other options are wrong

  • A. DNS poisoning corrupts DNS resolution, not the wireless connection itself.
  • B. Bluejacking involves sending unsolicited Bluetooth messages, unrelated to Wi-Fi.
  • D. MAC flooding targets switches to overwhelm the CAM table, not Wi-Fi clients.

Evil Twin

A rogue wireless access point disguised as a legitimate one to intercept user traffic or credentials.

  • Mimics legitimate SSID
  • Often has stronger signal to lure victims
  • Enables on-path attacks over Wi-Fi

Memory trick: Evil twin looks just like the real one, but it's rotten inside.

More Threats, Vulnerabilities, and Mitigations questions