Courseiva
mediumMultiple Choice

220-1102 Practice Question: A technician is investigating a security incident…

A technician is investigating a security incident where a user's credentials were stolen. The user says they only logged into their email from a coffee shop Wi-Fi. The technician notices that the browser was not using HTTPS for the login page. What is the most likely attack method used?

⚠ Common exam trap

The trap is selecting DNS spoofing because it also involves network manipulation, but the key clue is 'no HTTPS' and 'credentials stolen'—which directly points to cleartext interception via MITM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Man-in-the-middle attack.

A man-in-the-middle (MITM) attack occurs when an attacker intercepts communications between the user and the server, often on unsecured public Wi-Fi. Because the login page was not using HTTPS, credentials were transmitted in cleartext, allowing the attacker to capture them. This is the classic scenario for credential theft on open networks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cross-site scripting (XSS) attack.

    Why it's wrong here

    A Cross-site scripting (XSS) attack involves injecting malicious client-side scripts into web pages viewed by other users. While XSS can lead to session hijacking or credential theft by manipulating the user's browser, it operates by exploiting vulnerabilities in the web application itself, not by directly intercepting unencrypted HTTP traffic on the network layer. Therefore, it does not fit a scenario where credentials are stolen directly from Wi-Fi network communication.

  • ✓

    Man-in-the-middle attack.

    Why this is correct

    A Man-in-the-middle (MITM) attack is precisely what occurs when an attacker intercepts communication between two parties without their knowledge. In a Wi-Fi environment, an attacker can position themselves between a user and a legitimate login page, capturing all unencrypted HTTP traffic. Since HTTP does not encrypt data, any login credentials transmitted over it are exposed in plain text, allowing the attacker to easily steal them.

  • ✗

    DNS spoofing attack.

    Why it's wrong here

    DNS spoofing redirects traffic to a malicious server by corrupting DNS resolution, but the scenario describes the browser already reaching the legitimate login page over unencrypted HTTP, not being misdirected to a fake site. It is tempting because spoofing is a common method for credential theft in public Wi-Fi environments, and it would be correct if the user had typed a correct URL yet landed on a fraudulent page due to poisoned DNS cache.

  • ✗

    Brute force attack.

    Why it's wrong here

    A brute force attack involves systematically trying every possible combination of characters until the correct password or encryption key is found. This method relies on repeated, automated login attempts against a target system. The scenario describes a single login session where credentials are stolen from unencrypted network traffic, which is a passive interception rather than an active, iterative guessing process.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.