A security analyst is investigating a suspected rogue access point in the office. Which behavior most strongly indicates that a device is performing an Evil Twin attack?
Trap 1: The access point broadcasts a unique SSID that does not match…
Broadcasting a non-company SSID typically indicates a standard rogue AP, such as a user bringing in a home router. While this is a policy violation, it does not necessarily constitute an Evil Twin attack, which specifically requires mimicking a legitimate network to intercept client traffic.
Trap 2: The device has DHCP enabled and is assigning IP addresses from a…
Most consumer-grade routers default to DHCP, so this behavior is common for many types of rogue devices. It does not provide specific evidence of an Evil Twin attack, which is defined by the intentional spoofing of a legitimate network's identity to perform interception or credential harvesting.
Trap 3: The access point is connected directly to the corporate Ethernet…
A device connected to a corporate Ethernet drop is a significant security risk, but it does not define an Evil Twin attack. This is usually categorized as an unauthorized rogue AP that bridges the corporate network to the wireless medium, increasing the attack surface significantly.
- A
The access point broadcasts a unique SSID that does not match company policy.
Why it fails: Broadcasting a non-company SSID typically indicates a standard rogue AP, such as a user bringing in a home router. While this is a policy violation, it does not necessarily constitute an Evil Twin attack, which specifically requires mimicking a legitimate network to intercept client traffic.
- B
The access point shows a higher signal strength while using the same MAC address as a legitimate AP.
An Evil Twin specifically mimics the configuration of a known AP, including the SSID and MAC address, to force clients to roam to the stronger signal. This deceptive behavior is designed to transparently capture client traffic, which distinguishes it from a simple unauthorized rogue access point.
- C
The device has DHCP enabled and is assigning IP addresses from a private range.
Why it fails: Most consumer-grade routers default to DHCP, so this behavior is common for many types of rogue devices. It does not provide specific evidence of an Evil Twin attack, which is defined by the intentional spoofing of a legitimate network's identity to perform interception or credential harvesting.
- D
The access point is connected directly to the corporate Ethernet drop.
Why it fails: A device connected to a corporate Ethernet drop is a significant security risk, but it does not define an Evil Twin attack. This is usually categorized as an unauthorized rogue AP that bridges the corporate network to the wireless medium, increasing the attack surface significantly.