Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

Exhibit

Wireless scan from the lobby:
SSID: CorpWiFi       BSSID: 18:AA:10:22:44:60  Signal: -78 dBm
SSID: CorpWiFi       BSSID: 7C:22:90:11:33:AA  Signal: -41 dBm
SSID: CorpGuest      BSSID: 18:AA:10:22:44:61  Signal: -79 dBm
User report: "My tablet connected to CorpWiFi automatically, then a sign-in page appeared that looked different from our normal one."

Based on the exhibit, what wireless threat is most likely occurring?

⚠ Common exam trap

Watch out — candidates often confuse an evil twin with a rogue access point—a rogue AP is an unauthorized device plugged into the wired network, while an evil twin is a standalone attacker AP that mimics a legitimate SSID over the air.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Evil twin access point

The exhibit shows a legitimate access point (SSID: 'CorpNet') with a second, rogue access point broadcasting the same SSID but with a stronger signal. This is the classic behavior of an evil twin attack, where an attacker sets up a fraudulent AP to intercept client connections and capture credentials or sensitive data. The victim's device automatically associates with the stronger signal, believing it is the legitimate network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Evil twin access point

    Why this is correct

    Two access points are broadcasting the same SSID, but one has a much stronger signal and triggers a suspicious captive portal. That pattern fits an evil twin access point, which imitates a legitimate network to lure users into connecting. The attacker can then intercept traffic or harvest credentials.

  • Bluetooth pairing abuse

    Why it's wrong here

    Bluetooth pairing abuse exploits the short-range Bluetooth radio stack (typically ~10 meters) and involves pairing procedures like PIN/Passkey, Just Works, or Numeric Comparison. The exhibit shows two Wi-Fi access points broadcasting the same SSID, one with stronger signal and a suspicious captive portal — this is LAN-layer behavior, not Bluetooth. Bluetooth threats such as Bluejacking, Bluesnarfing, or BlueBorne do not create duplicate SSIDs or trigger web-based login portals. An attacker performing Bluetooth attacks would need to pair with a victim device, not spoof a network to lure connections.

  • NFC skimming

    Why it's wrong here

    NFC skimming is a proximity attack that targets near-field communication, which operates at less than 4 cm and is used for contactless payments, badges, or device pairing. Skimming typically involves an attacker placing an NFC reader near a victim's card or phone to harvest data passively. The evidence here involves wireless network access (SSIDs and a captive portal), which is a completely different OSI layer and range. NFC skimming would not involve broadcasting an SSID or serving a login page, and it requires the attacker to be physically closer than the exhibit implies.

  • DNS poisoning

    Why it's wrong here

    DNS poisoning corrupts the domain-name resolution system so that a legitimate hostname resolves to a malicious IP address, often achieved by injecting fake DNS records or compromising a DNS server. The exhibit shows two access points with the same SSID and a suspicious captive portal — that is a Layer 2/3 access-control issue, not a name-resolution failure. There is no evidence of modified DNS records, poisoned cache, or unusual IP resolution. Even though an evil twin could later be used to perform DNS redirection, the immediate indicator is the rogue AP and captive portal, not DNS manipulation.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.