CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
A user connects to a Wi-Fi network named 'Airport_Free_WiFi' that appears identical to the legitimate airport network but has a slightly stronger signal. After connecting, the user's traffic is intercepted. Which attack has most likely occurred?
- ADNS poisoning
- BBluejacking
- CEvil twin attack
- DMAC flooding
Show answer & explanationAnswer & explanation
Correct answer: C. Evil twin attack
An evil twin attack involves setting up a rogue access point with the same or similar SSID as a legitimate network to lure users into connecting, allowing the attacker to intercept traffic.
Why the other options are wrong
- A. DNS poisoning corrupts DNS resolution, not the wireless connection itself.
- B. Bluejacking involves sending unsolicited Bluetooth messages, unrelated to Wi-Fi.
- D. MAC flooding targets switches to overwhelm the CAM table, not Wi-Fi clients.
Evil Twin
A rogue wireless access point disguised as a legitimate one to intercept user traffic or credentials.
- Mimics legitimate SSID
- Often has stronger signal to lure victims
- Enables on-path attacks over Wi-Fi
Memory trick: Evil twin looks just like the real one, but it's rotten inside.