Soru

Zorluk: OrtaNetwork and Wireless Attack Indicators

A security analyst investigates anomalous wireless activity at a corporate branch office. Users report being prompted to re-enter their domain credentials on an unfamiliar web page while connected to the corporate Wi-Fi, and a Wireless Intrusion Prevention System (WIPS) flags abnormal access point behaviors. Which of the following technical indicators specifically point to an active Evil Twin attack performing credential harvesting? Select TWO.

  1. An unauthorized Basic Service Set Identifier (BSSID) broadcasting the legitimate corporate Service Set Identifier (SSID) with a higher signal strength.Cevap
  2. A continuous flood of 802.11 Deauthentication frames targeting legitimate connected clients to force them off the authorized access points.Cevap
  3. C
    An increase in ICMP Router Advertisement (RA) messages announcing a new default gateway link-local address.
  4. D
    A rapid surge in ARP Reply packets binding a single IP address to multiple distinct physical network interfaces across the switch stack.

Cevap

The technical indicators that confirm an active Evil Twin attack are the presence of an unauthorized BSSID broadcasting the legitimate SSID with a stronger signal strength, and a continuous flood of 802.11 Deauthentication frames forcing clients to disconnect from legitimate access points.
An Evil Twin attack relies on deploying a rogue access point that broadcasts the exact SSID of a legitimate wireless network, often operating at higher signal strength (RSSI) so client devices automatically connect to it. To accelerate client association, attackers typically transmit a flood of 802.11 Deauthentication management frames, disconnecting client devices from legitimate APs so they reconnect to the rogue AP.

Adım Adım Çözüm

1
Analyze the scenario requirements and attack symptoms
Identified that the attacker is impersonating an authorized corporate Wi-Fi access point to harvest user credentials.
Evil Twin attacks mimic legitimate wireless networks (SSID) while coercing wireless clients to connect to the attacker-controlled radio.
2
Evaluate wireless indicators for radio frequency impersonation and connection forcing
Connecting clients auto-associate with the strongest signal matching a known SSID (unauthorized BSSID with matching SSID), and deauthentication frames are used to force clients off legitimate APs.
Deauthentication frame floods drop existing legitimate connections, enabling the higher-power rogue BSSID to capture client reconnection requests.
3
Distinguish wireless layer indicators from wired network protocol attacks
Ruled out ICMP Router Advertisements (SLAAC attack indicator) and ARP poisoning (L2 Ethernet indicator) as they belong to wired segment protocol manipulation.
SLAAC and ARP attacks operate at Layer 2/3 of wired Ethernet networks rather than 802.11 wireless radio frequency association.

Anahtar Kavram

Evil Twin and Wireless Disassociation Attack Indicators
Bu soruyu puanla