CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography
An analyst captures the following output from a wireless adapter: `[00:1A:2B:3C:4D:5E] 54 Mbps WPA2 CCMP PSK`. The analyst suspects a malicious rogue AP is impersonating a legitimate network. Which of the following indicators would MOST strongly confirm a rogue AP?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The BSSID matches a known manufacturer, but the signal strength is unusually high
A rogue AP often has a higher signal strength than expected, especially if it's placed closer to users. Additionally, a mismatch between the BSSID and the known legitimate AP can indicate spoofing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The channel number is different from the legitimate AP
Why it's wrong here
Observing a different channel number from a known legitimate AP is not a definitive indicator of a rogue device. Legitimate access points frequently employ dynamic channel selection (DCS) or automatic channel selection (ACS) algorithms to optimize performance, minimize interference, and adapt to changing RF environments. Therefore, a channel change could simply reflect a normal operational adjustment by a legitimate AP rather than the presence of an unauthorized device.
- ✗
The SSID is broadcasted with the same name as the corporate network
Why it's wrong here
While rogue access points commonly broadcast an SSID identical to the corporate network to trick users into connecting, this factor alone is insufficient for confirmation. Enterprise wireless networks are designed with multiple legitimate access points all broadcasting the same SSID to facilitate seamless roaming and provide ubiquitous coverage. Therefore, a matching SSID is a necessary but not a unique characteristic of a rogue AP, requiring additional corroborating evidence.
- ✓
The BSSID matches a known manufacturer, but the signal strength is unusually high
Why this is correct
This combination is a strong indicator of a rogue AP. The Basic Service Set Identifier (BSSID), which is the MAC address of the AP, contains an Organizationally Unique Identifier (OUI) that identifies the manufacturer. While a rogue AP might spoof an OUI to appear legitimate, an unusually high signal strength for an AP not registered within the network's inventory strongly suggests a physically close, unauthorized device. This discrepancy between a potentially legitimate-looking identifier and an anomalous physical presence is highly suspicious.
- ✗
The encryption type is WPA2 with CCMP
Why it's wrong here
The presence of WPA2 with CCMP (Counter Mode with Cipher Block Chaining Message Authentication Code Protocol) as the encryption type is not an indicator of a rogue access point. WPA2-CCMP is the current industry standard for robust wireless security, offering strong authentication and encryption. Legitimate corporate networks are expected and encouraged to utilize WPA2-CCMP to protect their wireless communications, making its observation a sign of proper security implementation, not necessarily a threat.
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.