FC0-U71 Security Practice Question
An attacker sets up a fake wireless access point named "Cafe_Free_WiFi" in a coffee shop and uses it to capture the traffic of customers who connect. Which type of attack is this?
⚠ Common exam trap
It's easy for candidates to confuse an evil twin with a denial-of-service attack, because both can involve wireless interference, but only the evil twin impersonates a hotspot to intercept traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Evil twin
An evil twin is a rogue access point that impersonates a legitimate hotspot to trick users into connecting, enabling the attacker to capture or alter their traffic. The scenario's fake "Cafe_Free_WiFi" access point matches this definition precisely. Denial of service disrupts availability, while SQL injection and cross-site scripting are web application attacks unrelated to wireless impersonation and traffic interception.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Evil twin
Why this is correct
An evil twin is a rogue access point that imitates a legitimate hotspot to lure users into connecting, allowing the attacker to intercept or manipulate their traffic. The scenario describes exactly this: a fraudulent access point with an appealing name capturing customer data. It is a wireless-specific attack that exploits users' willingness to join open networks without verifying the hotspot's authenticity.
- ✗
Denial of service
Why it's wrong here
A denial-of-service attack aims to make a service unavailable, often by flooding it with traffic or disrupting wireless signals. The scenario does not describe service unavailability; instead, the attacker operates a working access point to intercept data. While a DoS attack could accompany an evil twin to push users toward the rogue AP, the primary described activity is traffic capture through impersonation, not disruption.
- ✗
Cross-site scripting
Why it's wrong here
Cross-site scripting injects malicious scripts into web pages viewed by other users, typically to steal session cookies or credentials within a browser context. It does not involve setting up a fake wireless access point or capturing traffic at the network layer. This option describes a web application vulnerability, not the wireless impersonation attack in the scenario.
- ✗
SQL injection
Why it's wrong here
SQL injection targets database-driven applications by inserting malicious SQL statements through input fields. It has nothing to do with wireless access points or capturing network traffic from coffee shop customers. This option confuses a web application attack with a wireless network attack, which are entirely different categories and require different defenses such as input validation versus wireless monitoring.
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.