ISC2 CC Network Security Practice Question
A security analyst notices that users on the corporate wireless network are occasionally redirected to a fraudulent login page when they browse to the company intranet. The analyst confirms the wireless access point is legitimate and that the rogue page presents a certificate issued by an unknown authority. Which attack is most likely occurring?
⚠ Common exam trap
The trap here is focusing on the wireless access point being legitimate and overlooking that interception can occur at other points on the path, such as through ARP or DHCP manipulation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An on-path attacker intercepting and modifying traffic
The untrusted certificate and fraudulent login page indicate that traffic between wireless clients and the intranet is being intercepted and altered. An on-path attacker can redirect requests and present a fake page, especially if users ignore certificate warnings. The legitimate access point rules out a rogue AP, but other interception techniques such as ARP or DHCP manipulation remain plausible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A cross-site scripting flaw in the intranet application
Why it's wrong here
Cross-site scripting executes attacker-supplied script in a victim's browser within the context of a trusted site, but it does not replace the site with a fraudulent login page served under an unknown certificate. The certificate warning indicates the client is talking to a different server, not that script is running inside the legitimate page. XSS also would not affect users browsing to the intranet before they even load the application.
- ✗
A denial-of-service flood against the intranet web server
Why it's wrong here
A denial-of-service flood would make the intranet unavailable or extremely slow, but it would not cause users to see a fraudulent login page with an untrusted certificate. The scenario describes content substitution rather than service disruption. DoS attacks consume resources and degrade availability; they do not typically redirect clients to attacker-controlled pages, so this does not match the observed behavior.
- ✗
A brute-force attack against the wireless authentication server
Why it's wrong here
Brute-force attacks repeatedly guess credentials to gain access to an authentication service. They do not redirect already-connected users to fraudulent pages or present untrusted certificates. If the wireless authentication server were being brute-forced, the symptom would be authentication failures or account lockouts, not users seeing a fake login page when browsing the intranet.
- ✓
An on-path attacker intercepting and modifying traffic
Why this is correct
An on-path attacker positioned between the wireless clients and the intranet can intercept requests and return a fraudulent login page. The untrusted certificate is consistent with the attacker terminating TLS with a self-signed or otherwise untrusted certificate. Because the access point is legitimate, the attacker is likely using techniques such as ARP spoofing, rogue DHCP, or a malicious proxy to insert themselves into the path.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.