N10-009 Network Security Practice Question
A security analyst is investigating a user's complaint that their wireless connection keeps disconnecting. The analyst uses a wireless scanning tool and discovers two access points broadcasting the same SSID 'CorpNet' with different BSSIDs. One is the legitimate company AP on channel 1, and the other is on channel 11 with a strong signal and security set to 'Open'. Which of the following attacks is most likely occurring?
⚠ Common exam trap
The N10-009 exam often tests the distinction between a rogue AP (an unauthorized device plugged into the wired network) and an evil twin (a standalone malicious AP that mimics the SSID without being connected to the corporate infrastructure), so candidates must remember that the key differentiator is the open security and different channel used to lure clients away from the legitimate AP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Evil twin
The presence of two access points broadcasting the same SSID 'CorpNet' with different BSSIDs, where the second AP is on channel 11 with a strong signal and security set to 'Open', is characteristic of an evil twin attack. The attacker sets up a fraudulent AP with the same SSID as the legitimate network but without encryption, tricking users into connecting to it and exposing their credentials or traffic. This differs from a rogue AP, which typically mimics the corporate network but may not necessarily use an open security setting or a different channel to lure victims.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
War driving
Why it's wrong here
War driving is a reconnaissance activity where an individual drives around with a Wi-Fi-enabled device to discover and map wireless networks. This process primarily involves passively scanning for access points, identifying their SSIDs, security protocols, and signal strengths, often to identify vulnerable networks. It does not involve actively setting up a malicious access point to trick users into connecting or intercepting their data.
When this WOULD be correct
War driving would be correct if the question described an attacker driving around a city to map wireless networks and identify vulnerable ones, without any mention of a fake AP or disconnection complaints.
- ✗
Rogue access point
Why it's wrong here
A rogue access point is any unauthorized access point connected to a network, often by an insider, that bypasses security controls. While an evil twin is technically a type of rogue AP, the term 'rogue AP' is broader and doesn't specifically imply the spoofing of a legitimate SSID to deceive users. The scenario's emphasis on an AP with the same SSID and open security points to the specific deceptive nature of an evil twin, making it a more precise classification.
When this WOULD be correct
A rogue access point would be correct if the question stated that an unauthorized AP was discovered connected to the company's wired network, potentially allowing bypass of security controls, without mention of spoofing the SSID or open security.
- ✓
Evil twin
Why this is correct
An evil twin attack involves an attacker setting up a malicious access point (AP) that mimics a legitimate Wi-Fi network's Service Set Identifier (SSID). This imposter AP often broadcasts with a stronger signal or open security to entice users to connect, allowing the attacker to intercept network traffic, harvest credentials, or inject malware. The scenario's description of two APs with the same SSID, one strong and open, perfectly matches this deceptive impersonation technique.
- ✗
Bluesnarfing
Why it's wrong here
Bluesnarfing is a specific type of attack targeting Bluetooth-enabled devices, not Wi-Fi networks. This attack exploits vulnerabilities in Bluetooth implementations to gain unauthorized access to data stored on a victim's device, such as contacts, messages, or calendar entries, without their knowledge or permission. It operates over short-range Bluetooth connections, fundamentally differing from Wi-Fi-based attacks like the one described in the question.
When this WOULD be correct
A user reports that their Bluetooth headset has been paired with an unknown device and they are experiencing audio dropouts. A security analyst discovers that an attacker is using a Bluetooth vulnerability to access the headset's contact list and call history. Bluesnarfing would be the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓Evil twinCorrect answer▾
Why this is correct
An evil twin attack involves an attacker setting up a malicious access point (AP) that mimics a legitimate Wi-Fi network's Service Set Identifier (SSID). This imposter AP often broadcasts with a stronger signal or open security to entice users to connect, allowing the attacker to intercept network traffic, harvest credentials, or inject malware. The scenario's description of two APs with the same SSID, one strong and open, perfectly matches this deceptive impersonation technique.
✗War drivingWrong answer — click to see why▾
Why this is wrong here
War driving is the act of searching for Wi-Fi wireless networks by a person in a moving vehicle, using a portable device. It does not involve setting up a fake access point to intercept connections, which is what the scenario describes.
★ When this WOULD be the correct answer
War driving would be correct if the question described an attacker driving around a city to map wireless networks and identify vulnerable ones, without any mention of a fake AP or disconnection complaints.
Why candidates choose this
Candidates may confuse war driving with any wireless attack involving scanning, because the scenario mentions using a wireless scanning tool, which is also used in war driving.
✗Rogue access pointWrong answer — click to see why▾
Why this is wrong here
A rogue access point is an unauthorized AP connected to the network, but the question describes an AP broadcasting the same SSID with an open security setting, which is characteristic of an evil twin attack, not a rogue AP.
★ When this WOULD be the correct answer
A rogue access point would be correct if the question stated that an unauthorized AP was discovered connected to the company's wired network, potentially allowing bypass of security controls, without mention of spoofing the SSID or open security.
Why candidates choose this
Candidates may confuse 'rogue access point' with any unauthorized wireless device, but the key distinction is that a rogue AP is physically connected to the network, whereas an evil twin merely mimics the SSID without network access.
✗BluesnarfingWrong answer — click to see why▾
Why this is wrong here
Bluesnarfing is an attack against Bluetooth devices, not Wi-Fi networks. The question describes a wireless disconnection issue involving two access points with the same SSID, which is a Wi-Fi attack scenario.
★ When this WOULD be the correct answer
A user reports that their Bluetooth headset has been paired with an unknown device and they are experiencing audio dropouts. A security analyst discovers that an attacker is using a Bluetooth vulnerability to access the headset's contact list and call history. Bluesnarfing would be the correct answer.
Why candidates choose this
Candidates may confuse 'Bluetooth' with 'wireless' or think that any wireless attack involving unauthorized access is bluesnarfing, without recognizing that bluesnarfing specifically targets Bluetooth connections.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Network Device Hardening
Key term
Evil twin
An evil twin attack is a rogue wireless access point that impersonates a legitimate network to intercept or manipulate user traffic.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
This N10-009 question is part of Courseiva's 464-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.