SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
Employees in a lobby report that their phones automatically connected to a wireless network named "CorpWiFi." Soon after, they were prompted to sign in through a web page that did not look like the normal company portal. What attack is most likely?
⚠ Common exam trap
Many exam-takers confuse an evil twin with a simple misconfiguration or a phishing attack, but the key indicator is the automatic connection to a network with the same SSID followed by a suspicious login page, which directly points to a rogue AP impersonating the legitimate network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Evil twin
The scenario describes an evil twin attack, where a rogue access point (AP) broadcasts a SSID identical to the legitimate corporate network ("CorpWiFi"). When employees' devices automatically connect to the stronger signal of the rogue AP, they are served a fake captive portal designed to capture credentials or other sensitive data. This attack exploits the lack of mutual authentication in standard 802.11 Wi-Fi associations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Bluetooth pairing attack
Why it's wrong here
A Bluetooth pairing attack (e.g., Bluejacking, Blueborne, or PIN cracking) exploits the Bluetooth radio stack to pair with or send data to a nearby device. However, the scenario describes devices connecting to a Wi-Fi SSID and being redirected to a browser-based sign-in page, which is classic captive portal behavior. Bluetooth operates over short-range PAN (IEEE 802.15.1), not over corporate LAN/WLAN infrastructure, and cannot intercept or clone a Wi-Fi network name. Thus, the symptoms are inconsistent with any Bluetooth-specific attack vector.
- ✓
Evil twin
Why this is correct
An evil twin is a rogue wireless access point that imitates a legitimate SSID so victims connect to it by mistake. The fake network name and suspicious sign-in page strongly suggest a malicious clone of the real Wi-Fi.
- ✗
NFC relay attack
Why it's wrong here
An NFC relay attack extends the range of contactless card/device transactions by bouncing signals between two NFC-capable tools, but NFC (ISO/IEC 14443) requires physical proximity of a few centimeters and operates at 13.56 MHz. The reported behavior involves phones automatically joining a wireless network and showing a suspicious login page, which indicates a Wi-Fi-level compromise. NFC cannot emulate a legitimate SSID, broadcast beacon frames, or serve an HTTP captive portal, so it is not a plausible cause in this scenario.
- ✗
MAC flooding
Why it's wrong here
MAC flooding is a Layer 2 switch attack where an attacker sends thousands of randomly sourced MAC frames to fill the Content Addressable Memory (CAM) table, forcing the switch into fail-open mode and enabling frame sniffing. This attack targets wired switch hardware and does not involve wireless access points, SSIDs, or captive portals. The symptoms described—phones joining a fake network and seeing a sign-in page—are caused by a rogue access point impersonating the legitimate WLAN, not by flooding switch forwarding tables. Moreover, MAC flooding would cause network disruptions or sniffing, not an authentication page.
Go deeper
Related to this question
Learn chapter
Network-Based Attacks
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,030 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.