Courseiva

SSCP Network and Communications Security Practice Question

A security analyst discovers that an attacker has set up a fake wireless access point with the same SSID as the corporate network. Users are unknowingly connecting to it. What is this attack called?

⚠ Common exam trap

It's easy for candidates to confuse the broad category 'rogue AP' with the specific impersonation attack 'evil twin' — the exam expects you to recognize that the matching SSID and user deception are the differentiators.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Evil twin

An evil twin is a rogue access point that impersonates a legitimate AP by broadcasting the same SSID (and often cloning the BSSID and security settings) to trick users into associating with it. Because clients auto-connect to known SSIDs, the attacker can harvest credentials, perform on-path (MITM) interception, or serve captive-portal phishing pages. The distinguishing feature is the deliberate imitation of a trusted network, which is exactly what the scenario describes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    KRACK

    Why it's wrong here

    KRACK exploits the WPA2 four-way handshake to replay and decrypt frames on a legitimate connection; it does not create a twin access point. KRACK would be correct where an attacker manipulates key reinstallation on an existing association rather than impersonating an AP.

  • ✗

    Rogue AP

    Why it's wrong here

    A rogue AP is an unauthorised access point physically connected to the wired network, not a same-SSID impersonation. The twin-SSID lure is an evil twin attack. Rogue AP is tempting because both involve unauthorised hardware, but rogue APs typically serve insider access rather than credential theft.

  • ✓

    Evil twin

    Why this is correct

    An evil twin is a rogue access point broadcasting the same SSID as the legitimate corporate network, often with a stronger signal, luring users into connecting so the attacker can intercept their traffic. This matches the stem's fake access point scenario exactly.

  • ✗

    PMKID attack

    Why it's wrong here

    A PMKID attack captures the pairwise master key identifier from a legitimate access point to crack the WPA2 handshake offline; it does not involve a rogue AP cloning an SSID. PMKID would be the answer where attackers harvest handshake material without client interaction.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.