PT0-002 Vulnerability Discovery and Analysis Practice Question
A tester wants to perform an evil twin attack to capture WPA handshakes. Which tool from the Aircrack-ng suite is used to deauthenticate clients from a legitimate AP to force reconnection to the rogue AP?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aireplay-ng
aireplay-ng can send deauthentication packets to disconnect clients, facilitating handshake capture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
airmon-ng
Why it's wrong here
airmon-ng is a wireless tool for enabling monitor mode on a network interface and managing wireless drivers, not for injecting frames. While monitor mode is a prerequisite for capturing traffic, airmon-ng itself does not generate any packets, so it cannot force a client to disconnect. The evil twin attack relies on deauthentication to lure clients onto the rogue AP, which requires packet injection—a capability exclusive to tools like aireplay-ng.
- ✗
airodump-ng
Why it's wrong here
airodump-ng is a packet capture utility that passively collects 802.11 frames, including handshakes, beacon frames, and management traffic. It does not transmit any data, so it cannot send deauthentication frames to disconnect a client from the legitimate AP. Although airodump-ng is essential for identifying target channels and clients, the actual deauth action in an evil twin attack is performed by a separate injection tool.
- ✗
aircrack-ng
Why it's wrong here
aircrack-ng is a post-capture offline cracking tool that analyzes WPA/WPA2 handshakes to recover the pre-shared key. It operates solely on saved packet captures and has no capability to inject frames into a live wireless network. In an evil twin attack, aircrack-ng could be used after capturing the handshake, but it cannot initiate the deauth that forces the client to reconnect to the rogue AP.
- ✓
aireplay-ng
Why this is correct
aireplay-ng is the correct tool because it can inject frames, specifically deauthentication packets, into a wireless network. Sending deauth frames to a connected client forcibly disconnects it from the legitimate AP, prompting it to reconnect—and the evil twin rogue AP can then capture the WPA handshake. While aireplay-ng also supports other injection attacks, its ability to actively disrupt client associations makes it the standard tool for the deauth phase of an evil twin attack.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.