CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography
Which of the following attacks is characterized by an attacker placing a fake wireless access point with the same SSID as a legitimate network to capture client credentials?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Evil twin attack
An evil twin attack involves setting up a rogue access point that mimics a legitimate SSID to intercept traffic and capture credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
De-authentication attack
Why it's wrong here
A de-authentication attack involves an attacker sending forged de-authentication frames to one or more clients, or to an access point, impersonating either the client or the AP. This forces legitimate clients to disconnect from the wireless network. While disruptive, this attack primarily focuses on denial of service by severing existing connections and does not inherently involve the creation of a rogue or fake access point to trick users into connecting.
- ✓
Evil twin attack
Why this is correct
An Evil Twin attack is precisely characterized by an attacker setting up a rogue access point (AP) that mimics the SSID and other characteristics of a legitimate, trusted Wi-Fi network. The objective is to trick unsuspecting users into connecting to the attacker's fake AP, believing it to be the legitimate one. Once connected, the attacker can intercept, monitor, or manipulate all network traffic, potentially capturing credentials or injecting malicious content.
- ✗
WPS PIN brute force attack
Why it's wrong here
A WPS PIN brute force attack specifically targets the Wi-Fi Protected Setup (WPS) feature, attempting to guess the eight-digit PIN required for easy device connection. Attackers exploit a design flaw in WPS that allows them to determine the PIN in two halves, significantly reducing the number of attempts needed. This attack aims to gain unauthorized access to an existing legitimate network by recovering its WPS PIN, rather than establishing a fake access point.
- ✗
Replay attack
Why it's wrong here
A replay attack involves an attacker intercepting legitimate data transmissions and then retransmitting them later to achieve an unauthorized effect. For instance, captured authentication credentials or session tokens can be "replayed" to gain access without knowing the actual secret. This method focuses on reusing valid captured data packets and does not involve the creation or operation of a fake access point to lure victims.
Go deeper
Related to this question
About these practice questions
One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.