Courseiva
Advanced Topics: Wireless, Cloud, IoT, CryptographymediumMultiple ChoiceObjective-mapped

CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography

A security analyst notices that after a user connects to a corporate Wi-Fi network, all HTTP traffic is redirected to a fake login page that captures credentials. The analyst suspects a rogue access point. Which attack is most likely being used to force client connections to the rogue AP?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

De-authentication attack followed by evil twin

De-authentication packets force clients to disconnect from the legitimate AP, after which they may automatically reconnect to a rogue AP with the same SSID. Evil twin is the fake AP, but the mechanism to disconnect clients is de-authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Evil twin attack using a stronger signal

    Why it's wrong here

    An evil twin attack involves a rogue access point (AP) impersonating a legitimate one, often with the same SSID. While a stronger signal might passively attract new connections in some scenarios, it typically cannot force an already connected client to disconnect from its legitimate AP and reassociate with the rogue AP. Active de-authentication frames are usually required to disrupt existing connections and prompt clients to search for a new, seemingly legitimate network.

  • WPA2 dictionary attack on the handshake

    Why it's wrong here

    A WPA2 dictionary attack aims to crack the Pre-Shared Key (PSK) by capturing the four-way handshake and then attempting to guess the passphrase against a list of common words or phrases. This attack method is used for gaining unauthorized access to the network itself by discovering the PSK, allowing a malicious actor to join the legitimate network. It does not involve redirecting client traffic to a fake login page or creating a rogue access point for phishing purposes.

  • WPS PIN brute-force attack

    Why it's wrong here

    A WPS PIN brute-force attack exploits a design flaw in Wi-Fi Protected Setup (WPS) to guess the router's 8-digit PIN, which then reveals the WPA2 Pre-Shared Key (PSK). The primary goal of this attack is to gain the actual network passphrase, enabling the attacker to connect to the legitimate Wi-Fi network as an authorized user. This method does not involve setting up a rogue access point or redirecting client traffic to a malicious login portal for credential harvesting.

  • De-authentication attack followed by evil twin

    Why this is correct

    A de-authentication attack floods a target client or access point with de-authentication frames, forcing the client to disconnect from the legitimate Wi-Fi network. Immediately following this disconnection, an attacker's "evil twin" access point, which mimics the legitimate network's SSID, becomes the most attractive network for the now-disconnected client. The client then automatically connects to this rogue AP, allowing the attacker to serve a fake login page to capture credentials or redirect traffic.

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.