Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A penetration tester is performing a wireless assessment and wants to set up an evil twin attack. Which of the following steps are necessary? (Choose THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a rogue access point with the same SSID as the target network

An evil twin attack involves creating a rogue access point with the same SSID as a legitimate network, deauthenticating clients, and capturing the handshake.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a rogue access point with the same SSID as the target network

    Why this is correct

    Cloning the target network's SSID is the essence of an evil twin attack because clients authenticate to networks by name and apparent signal strength rather than by verifying the AP's true identity. The attacker configures a rogue access point to broadcast the exact same SSID as the legitimate network, often also cloning the security type and any captive portal, so that a victim's device will associate with the attacker. Without this SSID masquerade, there is no evil twin with which to perform the subsequent steps of deauthentication and handshake capture.

  • ✗

    Configure WPA3 encryption on the rogue AP

    Why it's wrong here

    Using WPA3 encryption on the rogue AP is counterproductive because most evil twin engagements target WPA2-PSK networks, and the client expects a network object matching the legitimate AP's security profile. Furthermore, WPA3's Simultaneous Authentication of Equals (SAE) protocol provides key confirmation and forward secrecy that prevents the captured handshake from being used in an offline dictionary or brute-force attack, which is the central goal of the PSK-cracking phase. The attacker should instead emulate the target's existing security settings to maximize the chance that clients will roam to the impostor AP.

  • ✗

    Use Wireshark to decrypt the traffic

    Why it's wrong here

    Wireshark is a network protocol analyzer, not an attack-enabling tool, and its ability to decrypt WPA2 traffic depends on already knowing the WPA passphrase or having access to the derived PMK and session keys. During an evil twin setup, the passphrase is not yet known, so Wireshark would only display encrypted, unintelligible 802.11 frames. Decrypting captured traffic is a post-exploitation step that is only possible after the handshake is captured and the PSK has been cracked with a dedicated tool such as hashcat or aircrack-ng.

  • ✓

    Capture the WPA handshake when clients attempt to connect

    Why this is correct

    Capturing the WPA/WPA2 4-way handshake is a required step when the target uses WPA2-PSK, because the handshake exchanges EAPOL frames that contain the nonces and Message Integrity Checks needed to recover the pairwise master key from a guessed passphrase. When victims connect to the rogue AP, their device and the attacker's AP perform a handshake, which the attacker records in a file for offline cracking. Without that recorded handshake, the attacker has no cryptographic material to submit to password-guessing tools, even if clients have already been lured onto the evil twin.

  • ✓

    Send deauthentication frames to disconnect clients from the genuine AP

    Why this is correct

    Sending spoofed deauthentication frames that appear to come from the legitimate AP is a common way to accelerate an evil twin attack, since these management frames force connected clients to disconnect and rescan for available networks. When the rogue AP is broadcasting the same SSID with a stronger signal, the newly disconnected clients will often reassociate with the attacker and initiate a new WPA handshake, which can then be captured. Deauthentication is typically performed with aireplay-ng or mdk4 and is effective only if the target network does not enforce Protected Management Frames (802.11w).

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.