CISSP Communication and Network Security Practice Question
A security analyst discovers an attack where an attacker sets up a rogue wireless access point with a legitimate SSID to trick users into connecting. Once connected, the attacker captures credentials. This type of attack is known as:
⚠ Common exam trap
Candidates often confuse 'rogue AP' (any unauthorized AP) with 'evil twin' (a specific type of rogue AP that impersonates a legitimate SSID), leading them to choose option B instead of C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Evil twin attack
This is an evil twin attack because the attacker creates a rogue access point that broadcasts the same SSID as a legitimate network, tricking users into connecting to it. Once connected, the attacker can capture credentials or other sensitive data by acting as a man-in-the-middle. The key differentiator is the impersonation of a legitimate SSID to deceive users, not just the presence of an unauthorized AP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deauthentication attack
Why it's wrong here
A deauthentication attack involves an attacker sending forged deauthentication frames to one or more clients, or to the access point itself, impersonating either the client or the AP. This forces legitimate clients to disconnect from the wireless network, causing a denial of service. While it can be a precursor to other attacks, such as forcing a client to reconnect to a rogue AP, a deauthentication attack itself does not directly capture network credentials but rather disrupts service.
- ✗
Rogue AP attack
Why it's wrong here
A rogue AP attack involves an unauthorized access point installed on a network, often by an insider, or an attacker setting up an AP to lure unsuspecting users. This AP could be configured with any SSID and might not necessarily mimic an existing legitimate network. While an evil twin is a type of rogue AP, the term "rogue AP attack" is a broader category that doesn't specifically describe the act of impersonating a known, legitimate network's SSID to capture credentials.
- ✓
Evil twin attack
Why this is correct
An evil twin attack specifically involves an attacker setting up a malicious access point that mimics the SSID (Service Set Identifier) and often the MAC address of a legitimate, trusted wireless network. The objective is to trick unsuspecting users into connecting to the fraudulent AP, believing it to be the authentic network. Once connected, the attacker can intercept traffic, capture login credentials through fake portals, or launch further attacks, making it a highly effective method for credential harvesting.
- ✗
Karma attack
Why it's wrong here
A Karma attack operates by responding positively to *any* probe request sent by a client device, regardless of the SSID the client is searching for. This allows the malicious access point to trick clients into connecting to it by pretending to be any network the client has previously connected to. While it aims to lure clients, it differs from an evil twin in that it doesn't necessarily impersonate a *specific* legitimate network's SSID but rather exploits client behavior to connect to *any* known network.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Wireless access point
A wireless access point is a networking device that allows Wi-Fi-enabled devices to connect to a wired network, typically a local area network (LAN), acting as a bridge between wireless and wired communication.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.