Match each observed wireless attack indicator on the left with its corresponding attack classification on the right.
- Captive portal clone broadcasting an identical corporate SSID with a stronger RSSI on an unapproved channel alongside injected frame dropsEvil Twin Attack
- Unsolicited OBEX push messages containing text or contact cards received on mobile endpoints over short-range 2.4 GHz wireless linksBluejacking
- A high-frequency burst of 802.11 management frames (subtype 0x000C) forcing wireless clients off the access pointWireless Disassociation Attack
- Capture logs demonstrating repeated M4 and M6 message failures during automated PIN registration attempts against an APWPS Brute-Force Attack
Answer
1. Captive portal clone broadcasting identical SSID -> Evil Twin Attack; 2. Unsolicited OBEX push messages -> Bluejacking; 3. Burst of 802.11 management subtype 0x000C frames -> Wireless Disassociation Attack; 4. M4/M6 failure messages during PIN registration -> WPS Brute-Force Attack.
Each indicator uniquely aligns with its attack mechanism: Evil Twins impersonate known SSIDs with stronger RSSI; Bluejacking uses OBEX to deliver unsolicited media; Disassociation attacks utilize 802.11 management frames (subtype 0x000C); and WPS brute-forcing triggers M4/M6 handshake errors during PIN validation.
Step-by-Step Solution
Key Concept
Identifying wireless attack signatures and protocols from technical packet indicators and log anomalies.