SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
After a facilities outage, multiple employees report that their phones automatically joined a network named "CorpWiFi" in the lobby even though the legitimate access point was offline. A nearby attacker device then captured the captive portal login traffic. What attack is most likely?
⚠ Common exam trap
Candidates often confuse an evil twin with a rogue access point; candidates often pick 'rogue access point' because both involve unauthorized APs, but the key distinction is that an evil twin mimics a legitimate SSID to intercept traffic, while a rogue AP is physically connected to the internal network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Evil twin
Evil twin. In this scenario, the attacker set up a rogue access point with the same SSID ("CorpWiFi") as the legitimate network, which was offline. When employees' phones automatically attempted to reconnect to a known SSID, they associated with the attacker's device, which then presented a fake captive portal to capture login credentials. This is the classic definition of an evil twin attack: a fraudulent AP that mimics a legitimate one to intercept traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rogue access point
Why it's wrong here
A rogue access point is an unauthorized AP plugged into the wired network, often with no relation to the corporate SSID. Even if an attacker configures it with a cloned SSID, the core distinction is that a rogue AP typically bypasses security controls to gain network access rather than presenting a fake login portal. Here, the cloned SSID and captive credential prompt indicate an evil twin attack, not a simple rogue AP.
- ✓
Evil twin
Why this is correct
An evil twin is a fraudulent wireless network that imitates a trusted network's SSID and often broadcasts a stronger signal to cause clients to automatically roam to it. Once connected, the attacker presents a captive portal that mimics the legitimate login page, harvesting usernames and passwords. This exactly matches the reported symptoms of multiple employees connecting to a familiar SSID and being asked for credentials after a facility outage.
- ✗
Bluetooth bluejacking
Why it's wrong here
Bluejacking is a technique that sends unsolicited business-card messages to nearby Bluetooth-enabled devices, typically as an annoyance or prank. It does not create a Wi-Fi access point, spoof an SSID, or intercept network authentication credentials. Since the scenario involves wireless association and a portal login page, bluejacking cannot be the cause.
- ✗
NFC relay attack
Why it's wrong here
An NFC relay attack extends the range of near-field communication by using a proxy device to relay contactless signals from a victim's card or phone to a reader, often for payment fraud. It does not involve Wi-Fi connectivity, SSID spoofing, or a captive portal, and it requires close physical proximity to the victim's device. The reported symptoms of employees joining a fake Wi-Fi network and entering credentials are unrelated to NFC relay attacks.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.