SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
Exhibit
Wireless scan from the lobby: SSID: CorpWiFi BSSID: 18:AA:10:22:44:60 Signal: -78 dBm SSID: CorpWiFi BSSID: 7C:22:90:11:33:AA Signal: -41 dBm SSID: CorpGuest BSSID: 18:AA:10:22:44:61 Signal: -79 dBm User report: "My tablet connected to CorpWiFi automatically, then a sign-in page appeared that looked different from our normal one."
Based on the exhibit, what wireless threat is most likely occurring?
⚠ Common exam trap
Watch out — candidates often confuse an evil twin with a rogue access point—a rogue AP is an unauthorized device plugged into the wired network, while an evil twin is a standalone attacker AP that mimics a legitimate SSID over the air.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Evil twin access point
The exhibit shows a legitimate access point (SSID: 'CorpNet') with a second, rogue access point broadcasting the same SSID but with a stronger signal. This is the classic behavior of an evil twin attack, where an attacker sets up a fraudulent AP to intercept client connections and capture credentials or sensitive data. The victim's device automatically associates with the stronger signal, believing it is the legitimate network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Evil twin access point
Why this is correct
Two access points are broadcasting the same SSID, but one has a much stronger signal and triggers a suspicious captive portal. That pattern fits an evil twin access point, which imitates a legitimate network to lure users into connecting. The attacker can then intercept traffic or harvest credentials.
- ✗
Bluetooth pairing abuse
Why it's wrong here
Bluetooth pairing abuse exploits the short-range Bluetooth radio stack (typically ~10 meters) and involves pairing procedures like PIN/Passkey, Just Works, or Numeric Comparison. The exhibit shows two Wi-Fi access points broadcasting the same SSID, one with stronger signal and a suspicious captive portal — this is LAN-layer behavior, not Bluetooth. Bluetooth threats such as Bluejacking, Bluesnarfing, or BlueBorne do not create duplicate SSIDs or trigger web-based login portals. An attacker performing Bluetooth attacks would need to pair with a victim device, not spoof a network to lure connections.
- ✗
NFC skimming
Why it's wrong here
NFC skimming is a proximity attack that targets near-field communication, which operates at less than 4 cm and is used for contactless payments, badges, or device pairing. Skimming typically involves an attacker placing an NFC reader near a victim's card or phone to harvest data passively. The evidence here involves wireless network access (SSIDs and a captive portal), which is a completely different OSI layer and range. NFC skimming would not involve broadcasting an SSID or serving a login page, and it requires the attacker to be physically closer than the exhibit implies.
- ✗
DNS poisoning
Why it's wrong here
DNS poisoning corrupts the domain-name resolution system so that a legitimate hostname resolves to a malicious IP address, often achieved by injecting fake DNS records or compromising a DNS server. The exhibit shows two access points with the same SSID and a suspicious captive portal — that is a Layer 2/3 access-control issue, not a name-resolution failure. There is no evidence of modified DNS records, poisoned cache, or unusual IP resolution. Even though an evil twin could later be used to perform DNS redirection, the immediate indicator is the rogue AP and captive portal, not DNS manipulation.
Go deeper
Related to this question
Learn chapter
Network-Based Attacks
Key term
Evil twin
An evil twin attack is a rogue wireless access point that impersonates a legitimate network to intercept or manipulate user traffic.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.