CompTIA CySA+ (CS0-003)Security OperationsHard
A wireless intrusion detection system alerts on the following activity in a corporate office: - AP1: SSID "CorpWiFi", BSSID 00:1A:2B:3C:4D:5E, channel 6, signal strength -40 dBm - AP2: SSID "CorpWiFi", BSSID 00:1A:2B:3C:4D:99, channel 11, signal strength -35 dBm (new, unregistered) - A burst of deauthentication frames targeting clients connected to AP1 occurs immediately before several clients associate with AP2 Which of the following attacks does this activity MOST likely represent?
- AEvil twin attack
- BBluejacking attack
- CWPS PIN brute-force attack
- DRogue DHCP server attack
Show answer & explanationAnswer & explanation
Correct answer: A. Evil twin attack
An unregistered access point broadcasting the same SSID as the legitimate corporate network, combined with deauthentication frames forcing clients off the real AP so they reconnect to the attacker's AP, is the signature of an evil twin attack. The stronger signal (-35 dBm vs -40 dBm) further encourages clients to preferentially associate with the rogue AP.
Why the other options are wrong
- B. Bluejacking is a Bluetooth-based message-spam attack, unrelated to Wi-Fi APs.
- C. WPS brute force targets the WPS PIN mechanism, not SSID duplication or deauth flooding.
- D. A rogue DHCP server hands out malicious IP configuration but doesn't require a duplicate SSID or deauth frames.
Evil Twin Attack
A wireless attack where a rogue access point impersonates a legitimate AP's SSID, often paired with deauthentication attacks, to lure clients into connecting so traffic can be intercepted.
- Duplicate SSID with different BSSID/MAC
- Deauth frames force clients off the legitimate AP
- Stronger signal encourages client reassociation to rogue AP
Memory trick: Two APs, same name, one is an imposter twin.