Courseiva
Network Attacks And Defense StrategieseasyMultiple ChoiceObjective-mapped

CND Network Attacks And Defense Strategies Practice Question

A wireless security audit reveals that an unauthorized rogue access point has been deployed within the corporate perimeter, configured with the exact same SSID as the corporate enterprise network to perform an evil twin attack. Which enterprise wireless feature should the network administrator configure on the Wireless LAN Controller (WLC) to automatically detect and contain this rogue AP?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable Rogue AP Detection and Automated Containment on the Wireless LAN Controller (WLC).

Cisco Wireless LAN Controllers feature Rogue AP Detection and Automatic Containment (using Rogue Management and Adaptive Wireless Intrusion Prevention System - wIPS) which detects unauthorized APs broadcasting corporate SSIDs and sends deauthentication frames to isolate associated clients.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable Rogue AP Detection and Automated Containment on the Wireless LAN Controller (WLC).

    Why this is correct

    WLC rogue detection and containment automatically identifies and neutralizes evil twin access points.

  • Migrate the enterprise wireless network from WPA2-Personal to WPA3-Enterprise (SAE).

    Why it's wrong here

    While WPA3 improves security, WPA3-Personal/Enterprise alone does not automatically mitigate rogue AP containment.

  • Disable SSID broadcasting (hidden SSID) across all corporate wireless access points.

    Why it's wrong here

    Hidden SSIDs are easily discovered via probe requests and do not prevent evil twin attacks.

  • Configure MAC filtering to allow only corporate-approved wireless client hardware addresses.

    Why it's wrong here

    MAC filtering does not prevent rogue AP broadcasting or client association to the evil twin.

About these practice questions

Courseiva writes every CND question from scratch — 323 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.