ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 450 - SY0-601 discussion

Report
Export

A user reports constant lag and performance issues with the wireless network when working at a local coffee shop A security analyst walks the user through an installation of Wireshark and gets a five-minute pcap to analyze. The analyst observes the following output:

Which of the following attacks does the analyst most likely see in this packet capture?

A.
Session replay
Answers
A.
Session replay
B.
Evil twin
Answers
B.
Evil twin
C.
Bluejacking
Answers
C.
Bluejacking
D.
ARP poisoning
Answers
D.
ARP poisoning
Suggested answer: B

Explanation:

An evil twin is a type of wireless network attack that involves setting up a rogue access point that mimics a legitimate one. It can trick users into connecting to the rogue access point instead of the real one, and then intercept or modify their traffic, steal their credentials, launch phishing pages, etc.

In this packet capture, the analyst can see that there are two access points with the same SSID (CoffeeShop) but different MAC addresses (00:0c:41:82:9c:4f and 00:0c:41:82:9c:4e). This indicates that one of them is an evil twin that is trying to impersonate the other one.

asked 02/10/2024
Albaladejo Joffrey
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first