SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
Several employees in a branch office report that their laptops automatically connected to a network named "CorpWiFi" even though they were away from the office. Shortly afterward, a few users saw a captive portal asking them to re-enter company credentials. Which threat best explains this situation?
⚠ Common exam trap
It's easy for candidates to confuse an evil twin with a rogue AP that requires manual connection, but the key detail is the automatic connection, which exploits the client's saved network profile, not just the presence of a malicious AP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Evil twin access point impersonating the legitimate wireless network
The scenario describes an evil twin attack where a rogue access point broadcasts the SSID "CorpWiFi" to trick laptops into automatically connecting. Once connected, the attacker presents a fake captive portal to harvest credentials. This exploits the fact that client devices often prioritize known SSIDs without verifying the authenticity of the access point, relying solely on the network name.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Evil twin access point impersonating the legitimate wireless network
Why this is correct
An evil twin is a rogue access point configured to look like the trusted wireless network, often using the same or a very similar SSID. Because clients may auto-connect, attackers can capture credentials or inspect traffic through the fake network. The captive portal and automatic connection away from the office strongly suggest a malicious wireless impersonation setup.
- ✗
Bluetooth pairing abuse from a nearby device
Why it's wrong here
Bluetooth operates via frequency-hopping spread spectrum and requires an explicit pairing handshake, which is fundamentally different from Wi-Fi association with an SSID. Even if a nearby attacker exploited a Bluetooth vulnerability, that would not cause the laptop to automatically join a Wi-Fi network with a familiar name or present a captive portal. The described symptoms are specifically tied to 802.11 probe requests and association frames, which are entirely separate from Bluetooth's radio stack.
- ✗
DNS poisoning caused by a compromised resolver
Why it's wrong here
DNS poisoning corrupts the mapping of hostnames to IP addresses, so a user could be sent to a malicious website, but it operates at the application layer and has no influence over which wireless network a laptop connects to. The laptop's decision to associate with a rogue access point happens during the 802.11 scan/select process, which occurs before any DNS query is made. A compromised resolver would not produce a captive portal when the Wi-Fi adapter associates with an SSID; it merely redirects traffic after a connection is already established.
- ✗
NFC relay attack against the laptops' login process
Why it's wrong here
NFC is a short-range (a few centimeters) contactless technology used for things like tap-to-pay or Bluetooth pairing, and it does not participate in Wi-Fi network discovery or selection. An NFC relay attack could extend the range of a contactless transaction, but it cannot fool a laptop's wireless adapter into associating with a rogue access point or generate a captive portal. Furthermore, standard laptop login processes do not rely on NFC authentication, so this would have no bearing on the reported branch-office symptom.
Go deeper
Related to this question
Learn chapter
Network-Based Attacks
Key term
Evil twin
An evil twin attack is a rogue wireless access point that impersonates a legitimate network to intercept or manipulate user traffic.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.