CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A tester wants to harvest employee credentials during a physical/wireless assessment. The tester configures an access point broadcasting the same SSID as the corporate wireless network but with a stronger signal, and sets up a captive portal that mimics the company's login page. Which attack is being performed?

  1. ADeauthentication attack
  2. BKARMA attack
  3. CEvil twin attack
  4. DWPS PIN attack
Show answer & explanation

Correct answer: C. Evil twin attack

An evil twin attack involves creating a rogue access point that impersonates a legitimate SSID, often with a stronger signal and a fake captive portal, to trick users into connecting and submitting credentials.

Why the other options are wrong

  • A. Deauthentication attacks disconnect clients but do not involve a fake captive portal.
  • B. KARMA attacks respond to any probe request from clients, a related but distinct technique without necessarily mimicking one specific SSID.
  • D. WPS PIN attacks brute force the WPS PIN, not SSID impersonation.

Evil Twin Attack

A rogue access point that impersonates a legitimate network's SSID, often paired with a fake captive portal, to capture credentials or traffic.

  • Uses a stronger signal to lure clients away from the real AP
  • Often paired with a fake login page to harvest credentials
  • May be combined with deauth attacks to force reconnection

Memory trick: Twins look alike but one is evil in disguise.

More Attacks and Exploits questions