CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium
During a wireless assessment, a tester detects an access point broadcasting the corporate SSID but with a different BSSID, open authentication, and stronger signal strength than the legitimate AP. What is this most likely an example of?
- AEvil twin attack
- BWPS PIN brute force
- CDeauthentication flood
- DBluejacking
Show answer & explanationAnswer & explanation
Correct answer: A. Evil twin attack
An evil twin attack involves setting up a rogue access point that mimics a legitimate SSID, often with a stronger signal, to trick clients into connecting so traffic can be intercepted.
Why the other options are wrong
- B. WPS PIN brute force targets the WPS protocol, not SSID spoofing.
- C. A deauth flood disconnects clients but does not involve a spoofed SSID.
- D. Bluejacking targets Bluetooth devices, not Wi-Fi SSIDs.
Evil Twin Attack
A rogue access point configured to mimic a legitimate network's SSID in order to trick clients into connecting, enabling traffic interception.
- Often paired with deauthentication attacks to force reconnection
- Detected by comparing BSSIDs and signal characteristics
- Tools like WiFi Pineapple automate evil twin setup
Memory trick: 'Evil Twin Wears the Same Name'