401 SEC+ Exam Guaranteed Pass: Expert-Verified
Questions with Complete Solutions for Academic
Excellence
After a recent breach, the security administrator performs a wireless survey of the
corporate network. The security administrator notices a problem with the following output:
MACSSIDENCRYPTIONPOWERBEACONS
00:10:A1:36:12:CCMYCORPWPA2 CCMP601202
00:10:A1:49:FC:37MYCORPWPA2 CCMP709102
FB:90:11:42:FA:99MYCORPWPA2 CCMP403031
00:10:A1:AA:BB:CCMYCORPWPA2 CCMP552021
00:10:A1:FA:B1:07MYCORPWPA2 CCMP306044
Given that the corporate wireless network has been standardized, which of the following
attacks is underway?
A. Evil twin
B. IV attack
C. Rogue AP
D. DDoS - -correct ans- -Answer: A
Explanation:
The question states that the corporate wireless network has been standardized. By
'standardized' it means the wireless network access points are running on hardware from
the same vendor. We can see this from the MAC addresses used. The first half of a MAC
address is vendor specific. The second half is network adapter specific. We have four
devices with MAC addresses that start with 00:10:A1.
The "odd one out" is the device with a MAC address starting FB:90:11. This device is from a
different vendor. The SSID of the wireless network on this access point is the same as the
other legitimate access points. Therefore, the access point with a MAC address starting
FB:90:11 is impersonating the corporate access points. This is known as an Evil Twin.
,An evil twin, in the context of network security, is a rogue or fake wireless access point
(WAP) that appears as a genuine hotspot offered by a legitimate provider.
In an evil twin attack, an eavesdropper or hacker fraudulently creates this rogue hotspot to
collect the personal data of unsuspecting users. Sensitive data can be stolen by spying on
a connection or using a phishing technique.
For example, a hacker using an evil twin exploit may be positioned near an authentic Wi-Fi
access point and discover the service set identifier (SSID) and frequency. The hacker may
then send a radio signal using the exact same frequency and SSID. To end users, the rogue
evil twin appears as their legitimate hotspot with the same name.
In wireless transmissions, evil twins are not a new phenomenon. Historically, they were
known as honeypots or base station clones. With the advancement of wireless technology
and the use of wireless devices in public areas, it is very easy for novice users to set up evil
twin exploits.
Which of the following types of wireless attacks would be used specifically to impersonate
another WAP in order to gain unauthorized information from mobile users?
A. IV attack
B. Evil twin
C. War driving
D. Rogue access point - -correct ans- -Answer: B
Explanation:
An evil twin, in the context of network security, is a rogue or fake wireless access point
(WAP) that appears as a genuine hotspot offered by a legitimate provider.
In an evil twin attack, an eavesdropper or hacker fraudulently creates this rogue hotspot to
collect the personal data of unsuspecting users. Sensitive data can be stolen by spying on
a connection or using a phishing technique.
For example, a hacker using an evil twin exploit may be positioned near an authentic Wi-Fi
access point and discover the service set identifier (SSID) and frequency. The hacker may
then send a radio signal using the exact same frequency and SSID. To end users, the rogue
evil twin appears as their legitimate hotspot with the same name.
, In wireless transmissions, evil twins are not a new phenomenon. Historically, they were
known as honeypots or base station clones. With the advancement of wireless technology
and the use of wireless devices in public areas, it is very easy for novice users to set up evil
twin exploits.
Which of the following attacks would cause all mobile devices to lose their association with
corporate access points while the attack is underway?
A. Wireless jamming
B. Evil twin
C. Rogue AP
D. Packet sniffing - -correct ans- -Answer: A
Explanation:
When most people think of frequency jamming, what comes to mind are radio, radar and
cell phone jamming. However, any communication that uses radio frequencies can be
jammed by a strong radio signal in the same frequency. In this manner, Wi-Fi may be
attacked with a network jamming attack, reducing signal quality until it becomes unusable
or disconnects occur. With very similar methods, a focused and aimed signal can actually
break access point hardware, as with equipment destruction attacks.
The system administrator has been notified that many users are having difficulty
connecting to the company's wireless network. They take a new laptop and physically go to
the access point and connect with no problems. Which of the following would be the MOST
likely cause?
A. The certificate used to authenticate users has been compromised and revoked.
B. Multiple war drivers in the parking lot have exhausted all available IPs from the pool to
deny access.
C. An attacker has gained access to the access point and has changed the encryption keys.
D. An unauthorized access point has been configured to operate on the same channel. - -
correct ans- -Answer: D
Questions with Complete Solutions for Academic
Excellence
After a recent breach, the security administrator performs a wireless survey of the
corporate network. The security administrator notices a problem with the following output:
MACSSIDENCRYPTIONPOWERBEACONS
00:10:A1:36:12:CCMYCORPWPA2 CCMP601202
00:10:A1:49:FC:37MYCORPWPA2 CCMP709102
FB:90:11:42:FA:99MYCORPWPA2 CCMP403031
00:10:A1:AA:BB:CCMYCORPWPA2 CCMP552021
00:10:A1:FA:B1:07MYCORPWPA2 CCMP306044
Given that the corporate wireless network has been standardized, which of the following
attacks is underway?
A. Evil twin
B. IV attack
C. Rogue AP
D. DDoS - -correct ans- -Answer: A
Explanation:
The question states that the corporate wireless network has been standardized. By
'standardized' it means the wireless network access points are running on hardware from
the same vendor. We can see this from the MAC addresses used. The first half of a MAC
address is vendor specific. The second half is network adapter specific. We have four
devices with MAC addresses that start with 00:10:A1.
The "odd one out" is the device with a MAC address starting FB:90:11. This device is from a
different vendor. The SSID of the wireless network on this access point is the same as the
other legitimate access points. Therefore, the access point with a MAC address starting
FB:90:11 is impersonating the corporate access points. This is known as an Evil Twin.
,An evil twin, in the context of network security, is a rogue or fake wireless access point
(WAP) that appears as a genuine hotspot offered by a legitimate provider.
In an evil twin attack, an eavesdropper or hacker fraudulently creates this rogue hotspot to
collect the personal data of unsuspecting users. Sensitive data can be stolen by spying on
a connection or using a phishing technique.
For example, a hacker using an evil twin exploit may be positioned near an authentic Wi-Fi
access point and discover the service set identifier (SSID) and frequency. The hacker may
then send a radio signal using the exact same frequency and SSID. To end users, the rogue
evil twin appears as their legitimate hotspot with the same name.
In wireless transmissions, evil twins are not a new phenomenon. Historically, they were
known as honeypots or base station clones. With the advancement of wireless technology
and the use of wireless devices in public areas, it is very easy for novice users to set up evil
twin exploits.
Which of the following types of wireless attacks would be used specifically to impersonate
another WAP in order to gain unauthorized information from mobile users?
A. IV attack
B. Evil twin
C. War driving
D. Rogue access point - -correct ans- -Answer: B
Explanation:
An evil twin, in the context of network security, is a rogue or fake wireless access point
(WAP) that appears as a genuine hotspot offered by a legitimate provider.
In an evil twin attack, an eavesdropper or hacker fraudulently creates this rogue hotspot to
collect the personal data of unsuspecting users. Sensitive data can be stolen by spying on
a connection or using a phishing technique.
For example, a hacker using an evil twin exploit may be positioned near an authentic Wi-Fi
access point and discover the service set identifier (SSID) and frequency. The hacker may
then send a radio signal using the exact same frequency and SSID. To end users, the rogue
evil twin appears as their legitimate hotspot with the same name.
, In wireless transmissions, evil twins are not a new phenomenon. Historically, they were
known as honeypots or base station clones. With the advancement of wireless technology
and the use of wireless devices in public areas, it is very easy for novice users to set up evil
twin exploits.
Which of the following attacks would cause all mobile devices to lose their association with
corporate access points while the attack is underway?
A. Wireless jamming
B. Evil twin
C. Rogue AP
D. Packet sniffing - -correct ans- -Answer: A
Explanation:
When most people think of frequency jamming, what comes to mind are radio, radar and
cell phone jamming. However, any communication that uses radio frequencies can be
jammed by a strong radio signal in the same frequency. In this manner, Wi-Fi may be
attacked with a network jamming attack, reducing signal quality until it becomes unusable
or disconnects occur. With very similar methods, a focused and aimed signal can actually
break access point hardware, as with equipment destruction attacks.
The system administrator has been notified that many users are having difficulty
connecting to the company's wireless network. They take a new laptop and physically go to
the access point and connect with no problems. Which of the following would be the MOST
likely cause?
A. The certificate used to authenticate users has been compromised and revoked.
B. Multiple war drivers in the parking lot have exhausted all available IPs from the pool to
deny access.
C. An attacker has gained access to the access point and has changed the encryption keys.
D. An unauthorized access point has been configured to operate on the same channel. - -
correct ans- -Answer: D