A mobile user working remotely at an airport lounge reports that their corporate smartphone automatically connected to an unencrypted Wi-Fi network named "Enterprise-WiFi", which matches the SSID of their company's main office network. Shortly afterward, the user begins receiving security warnings about invalid SSL/TLS certificates when attempting to open internal enterprise applications. Which of the following represents the MOST likely root cause of this security incident?
- A rogue access point (Evil Twin) is broadcasting a duplicate corporate SSID to intercept client traffic.Cevap
- BThe corporate Mobile Device Management (MDM) enrollment profile expired, forcing authentication back to public cellular towers.
- CThe mobile device automatically negotiated a fallback from WPA3-Enterprise to WPA2-Personal due to weak signal strength.
- DA malicious sideloaded application modified local permissions to bypass corporate VPN domain name resolution.
Cevap
A rogue access point (Evil Twin) is broadcasting a duplicate corporate SSID to intercept client traffic.
The scenario describes an Evil Twin attack where an attacker sets up a rogue wireless access point with an SSID matching a known legitimate network ('Enterprise-WiFi'). Because the mobile device previously saved this network name, it automatically connects to the attacker's unencrypted AP. When the attacker attempts to intercept HTTPS traffic via Man-in-the-Middle (MitM), the invalid SSL/TLS certificate warnings are triggered.
Adım Adım Çözüm
Anahtar Kavram
Rogue Access Point / Evil Twin Detection and Symptoms