CISSP Communication and Network Security Practice Question
During a penetration test, an ethical hacker sets up a rogue access point with the same SSID as the corporate network and broadcasts a stronger signal. Users inadvertently connect to the rogue AP, allowing the hacker to capture credentials. What is this attack called?
⚠ Common exam trap
Candidates often confuse 'Evil twin' with 'Karma attack' because both involve rogue APs, but Karma attack specifically targets probe requests to impersonate any SSID the client has previously trusted, whereas an evil twin broadcasts a specific SSID to mimic a known network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Evil twin attack
Evil twin attack. This attack involves setting up a rogue access point that broadcasts the same SSID as a legitimate corporate network but with a stronger signal, causing users to connect to it instead. Once connected, the attacker can capture credentials or other sensitive data through man-in-the-middle techniques, exploiting the lack of mutual authentication in many Wi-Fi implementations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deauthentication attack
Why it's wrong here
A deauthentication attack involves an attacker sending specially crafted deauthentication frames to one or more clients, or to the access point (AP) itself, impersonating either the client or the AP. This forces legitimate clients to disconnect from the wireless network, often to capture a WPA/WPA2 handshake during re-association. However, this attack focuses on disrupting existing connections rather than establishing a rogue access point to impersonate a legitimate one.
- ✗
ARP spoofing
Why it's wrong here
ARP spoofing, also known as ARP poisoning, is a Layer 2 attack that involves an attacker sending forged Address Resolution Protocol (ARP) messages onto a local area network. This causes the attacker's MAC address to be associated with the IP address of another host, such as the default gateway, on the victim's ARP cache. While it can be performed on a wired or wireless network, it manipulates network traffic flow within an existing network and does not involve establishing a rogue access point to mimic a legitimate one.
- ✓
Evil twin attack
Why this is correct
An evil twin attack involves an attacker setting up a rogue wireless access point (AP) that mimics the SSID and often the security configuration of a legitimate, trusted Wi-Fi network. The goal is to trick unsuspecting users into connecting to the attacker's AP instead of the genuine one. Once connected, the attacker can intercept network traffic, capture credentials, or launch further attacks, making it a highly effective method for impersonating a legitimate network.
- ✗
Karma attack
Why it's wrong here
A Karma attack is a specific type of rogue AP attack where the attacker's access point passively listens for probe requests from clients that are searching for previously connected, preferred networks. The rogue AP then responds to *any* such probe request, regardless of the requested SSID, by advertising itself as that preferred network. This technique exploits client behavior to trick devices into automatically connecting to the attacker's AP, but it's distinct from an evil twin which actively broadcasts a specific, known SSID.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.