Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

Employees in a lobby say their phones automatically connected to a wireless network named CorpWiFi, even though the legitimate access point was offline. They were then shown a fake sign-in page. What threat is this?

⚠ Common exam trap

A common mix-up: candidates confuse an evil twin with a rogue access point, but the key distinction is that an evil twin specifically impersonates a legitimate SSID to trick clients into connecting, whereas a rogue AP is simply an unauthorized device on the network.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

An evil twin access point impersonating the real corporate wireless network

This is an evil twin attack. The attacker sets up a rogue access point broadcasting the same SSID (CorpWiFi) as the legitimate network. When the real access point goes offline, client devices automatically connect to the stronger signal of the rogue AP, allowing the attacker to present a fake captive portal to harvest credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • An evil twin access point impersonating the real corporate wireless network

    Why this is correct

    An evil twin is a rogue access point that advertises the exact service set identifier (SSID) of the legitimate corporate wireless network, often on a stronger signal than the real AP. Because many devices are configured to auto-reconnect to previously joined SSIDs, they will associate with the evil twin without any user intervention. Once connected, the attacker sits in the middle, presenting a phishing login page or harvesting credentials. In a lobby, an attacker can easily deploy this using a small battery-powered Wi-Fi device, making it the correct explanation.

  • A Bluetooth replay attack that reuses captured pairing data

    Why it's wrong here

    A Bluetooth replay attack focuses on capturing and retransmitting Bluetooth pairing or authentication packets at the link layer, not on mimicking an 802.11 Wi-Fi SSID. Such an attack could impersonate a Bluetooth device that was previously paired, but it cannot create a visible fake corporate wireless network or a captive portal login page. The phones in the lobby connected to a Wi-Fi network automatically, which is a wireless LAN (802.11) association event, not a Bluetooth protocol reuse event.

  • A cloud misconfiguration exposing a storage bucket to the internet

    Why it's wrong here

    A cloud misconfiguration, such as an open Amazon S3 bucket or Azure Blob container, exposes stored objects directly over HTTPS via predictable URLs. This could leak sensitive files or allow data tampering, but it has zero effect on the radio-frequency environment in a lobby. It would not cause phones to see, select, or auto-connect to a fake SSID, and it does not involve an access point, beacon frames, or a login page. The attack surface is an internet-facing storage service, not a wireless network impersonation.

  • A dependency compromise in a software library used by the company portal

    Why it's wrong here

    A dependency compromise (supply-chain attack) occurs when a malicious library is inserted into the software build, affecting the corporate portal's code at runtime. While it could alter the portal's behavior, inject malicious scripts, or steal data from users visiting the portal, it cannot broadcast a wireless SSID or cause phones to disconnect from a legitimate AP and join a rogue one. The compromise is in the application layer via network requests to the portal, not in the physical layer or 802.11 management frames. Therefore, it fails to explain the direct wireless association anomaly described in the scenario.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Employees in a lobby report that their phones automatically connected to a wireless network named "CorpWiFi." Soon after, they were prompted to sign in through a web page that did not look like the normal company portal. What attack is most likely?

easy
  • A.Bluetooth pairing attack
  • B.Evil twin
  • C.NFC relay attack
  • D.MAC flooding

Why B: The scenario describes an evil twin attack, where a rogue access point (AP) broadcasts a SSID identical to the legitimate corporate network ("CorpWiFi"). When employees' devices automatically connect to the stronger signal of the rogue AP, they are served a fake captive portal designed to capture credentials or other sensitive data. This attack exploits the lack of mutual authentication in standard 802.11 Wi-Fi associations.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.