Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

A penetration tester is authorized to test a company's wireless network. After capturing the WPA2 4-way handshake, the tester attempts to crack it offline but fails because the passphrase is long and complex. The tester then decides to create a rogue access point that mimics the corporate SSID and captures the handshake from a connecting client. Which attack is the tester performing?

⚠ Common exam trap

Test-takers frequently confuse an evil twin with a deauthentication attack, since both can be used to capture a handshake, but only the evil twin involves a rogue access point mimicking a legitimate SSID.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Evil twin

The tester sets up a rogue access point with the same SSID as the corporate network to trick a client into connecting, thereby capturing the WPA2 handshake. This is the definition of an evil twin attack. The other options describe different wireless attacks that do not match the scenario's details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPS PIN brute force

    Why it's wrong here

    WPS PIN brute force attacks the 8-digit PIN used in Wi-Fi Protected Setup to recover the WPA/WPA2 passphrase. The scenario does not mention WPS; it involves capturing a handshake via a fake AP. Thus, this attack is not applicable here.

  • ✓

    Evil twin

    Why this is correct

    An evil twin is a rogue access point that impersonates a legitimate Wi-Fi network to trick clients into connecting. Once the victim connects, the attacker can capture the WPA2 handshake or credentials. This matches the scenario where the tester creates a fake AP with the corporate SSID to capture the handshake from a connecting client.

  • ✗

    Deauthentication attack

    Why it's wrong here

    A deauthentication attack sends forged 802.11 deauth frames to disconnect clients from an AP, forcing them to reconnect and reveal the handshake. However, the scenario describes creating a rogue access point that mimics the corporate SSID, not sending deauth frames. Therefore, this is not the attack being performed.

  • ✗

    KRACK attack

    Why it's wrong here

    KRACK exploits vulnerabilities in the WPA2 4-way handshake to decrypt traffic or inject packets. The tester in the scenario is not exploiting a protocol flaw but rather creating a rogue AP to capture the handshake. Therefore, KRACK is not the correct answer.

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.