Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

During a conference, several employees connect to a wireless network named the same as the hotel's guest Wi-Fi. Shortly after connecting, they receive certificate warnings when accessing the company portal, and packet capture shows a nearby laptop advertising the same SSID and relaying traffic. What type of attack is most likely?

⚠ Common exam trap

Watch out — candidates often confuse an evil twin with a simple rogue access point, but the key differentiator is that the evil twin specifically impersonates a legitimate SSID to trick users, while a rogue AP might use a different SSID; the certificate warning and relayed traffic confirm the man-in-the-middle role, not just unauthorized access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Rogue access point or evil twin attack, because a fake wireless network impersonates a legitimate one.

The attack described is an evil twin (a type of rogue access point) because the attacker sets up a laptop broadcasting the same SSID as the hotel's legitimate guest Wi-Fi. When employees connect to this fake network, the attacker can intercept traffic and present a fraudulent certificate for the company portal, triggering certificate warnings. The packet capture confirming the laptop is relaying traffic proves it is acting as a man-in-the-middle, not merely a passive listener.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Rogue access point or evil twin attack, because a fake wireless network impersonates a legitimate one.

    Why this is correct

    An evil twin is a rogue access point that broadcasts the same SSID as a legitimate corporate network, often with a stronger signal, causing nearby clients to auto-associate. Once connected, the attacker can perform man-in-the-middle attacks, capture authentication credentials, or redirect users to malicious sites. This precisely matches the conference scenario, where employees are lured to a fake wireless network that impersonates a trusted one.

  • Replay attack, because previously captured wireless frames are being resent to the network.

    Why it's wrong here

    A replay attack involves capturing valid wireless frames—such as a WPA2 four-way handshake—and retransmitting them later to fool the network into granting access or to impersonate a client. The key symptom here is a malicious access point actively broadcasting a legitimate network name, not the passive retransmission of previously recorded traffic. Because the scenario describes employees voluntarily connecting to a counterfeit SSID, it fits an evil twin rather than a replay mechanism.

  • DNS poisoning, because users are being sent to the wrong website through altered name resolution.

    Why it's wrong here

    DNS poisoning corrupts the name resolution process by injecting false records into a DNS cache, causing users to be sent to a malicious IP address when they request a legitimate domain. In this wireless scenario, the initial compromise occurs at the association layer when clients connect to a rogue AP that impersonates the corporate SSID, allowing direct interception of traffic without any alteration to DNS servers. The attack described is a Layer 2 impersonation, not a Layer 7 name-resolution manipulation.

  • Denial of service, because users are simply unable to connect reliably.

    Why it's wrong here

    A denial-of-service attack on wireless aims to make the network unavailable, typically through deauthentication flooding, channel jamming, or overwhelming the AP with associate requests. While an evil twin may cause temporary connectivity issues because clients associate to the wrong AP, the attacker's goal here is to intercept and steal credentials, not to disrupt service. The presence of a fake network that lures users in contradicts the DoS objective, which is to prevent access rather than gain it.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.