Courseiva
Advanced Topics: Wireless, Cloud, IoT, CryptographymediumMultiple ChoiceObjective-mapped

CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography

An attacker sets up a fake access point with the same SSID as a legitimate corporate network. Clients connecting to this AP are prompted to enter their network credentials. Which type of attack is this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Evil twin attack

The attack is an evil twin attack, where a rogue AP mimics a legitimate one to capture credentials or perform man-in-the-middle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Replay attack

    Why it's wrong here

    A replay attack involves an attacker passively capturing legitimate data transmissions, such as authentication requests or session tokens, and then retransmitting them later to impersonate a legitimate user or gain unauthorized access. This method focuses on manipulating existing network traffic rather than establishing a fraudulent network infrastructure like a fake access point. It exploits the lack of proper session freshness or unique nonces in communication protocols, making it distinct from network impersonation.

  • Evil twin attack

    Why this is correct

    An evil twin attack specifically involves an attacker setting up a rogue wireless access point that mimics the SSID and often the MAC address of a legitimate, trusted network. The objective is to trick unsuspecting users into connecting to this malicious AP, allowing the attacker to intercept all their network traffic, perform man-in-the-middle attacks, or phish credentials. This direct impersonation of a legitimate Wi-Fi network by creating a fake AP with the same SSID is precisely what the question describes.

  • WPS PIN attack

    Why it's wrong here

    A WPS PIN attack exploits a design flaw in the Wi-Fi Protected Setup (WPS) protocol, which allows for a brute-force attack against the 8-digit PIN. The vulnerability arises because the AP validates the PIN in two halves, significantly reducing the number of attempts needed to guess the correct code and recover the Pre-Shared Key (PSK). This attack specifically targets the WPS authentication mechanism and does not involve creating a fake access point to lure clients.

  • De-authentication attack

    Why it's wrong here

    A de-authentication attack involves an attacker sending forged de-authentication frames to one or more clients, or to the access point itself, forcing legitimate users to disconnect from the network. This denial-of-service technique disrupts client connectivity but does not involve setting up a fake access point or impersonating a legitimate network. It is often used as a precursor to other attacks, such as forcing clients to reconnect to an attacker-controlled evil twin AP, but it is not the act of establishing the fake AP itself.

About these practice questions

This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CEH

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An attacker sets up a rogue access point with the same SSID as a legitimate corporate network and broadcasts a stronger signal. Clients connect to the rogue AP. What type of attack is this?

medium
  • A.WPS PIN attack
  • B.De-authentication attack
  • C.Evil twin attack
  • D.MAC spoofing attack

Why C: An evil twin attack involves a rogue AP mimicking a legitimate SSID to intercept traffic.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.