220-1102 exam dumps

220-1102 practice question 443 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 443

Single answerEvil twin

A company employee reports that while working from a coffee shop, their laptop briefly disconnected from Wi-Fi and then reconnected to a network with the same name as the coffee shop's wireless network. Immediately afterward, the employee was prompted to sign in again to a web portal, and the connection became unusually slow. The help desk suspects an evil twin attack. Which action should the technician recommend FIRST to reduce the employee's immediate risk?

  1. A

    Disconnect from the wireless network and verify the hotspot with staff before reconnecting

  2. B

    Forget the SSID permanently and disable all wireless networking on the laptop

  3. C

    Renew the laptop's IP address to obtain a valid lease from the access point

  4. D

    Change the laptop's local administrator password to prevent credential theft

Show answer and explanation

Correct answer: A

Explanation

An evil twin is a fraudulent wireless access point configured to look like a legitimate hotspot, usually by copying the same SSID and offering a stronger signal or easier connection. The goal is often to trick users into joining the rogue network so an attacker can intercept traffic, present a fake captive portal, or capture credentials. In a real-world support scenario, the first priority is containment: disconnect from the suspicious Wi-Fi immediately. After that, the user should verify the legitimate hotspot with a trusted source, such as venue staff, before reconnecting. Additional best practices include avoiding sensitive logins on public Wi-Fi, using VPNs on untrusted networks, disabling auto-connect to open networks, and confirming HTTPS connections. These recommendations align with common security best practices for wireless threat mitigation and user awareness covered in CompTIA A+ Core 2 security objectives.

  • A. Correct.

    This is the best first step. An evil twin attack involves a rogue access point impersonating a legitimate wireless network, often using the same SSID to trick users into connecting. The immediate priority is to stop using the potentially malicious connection, then verify the legitimate network name and connection details with trusted staff before reconnecting. This reduces the chance of further interception of traffic or credential capture.

  • B. Incorrect.

    This is too extreme and not the best first response. Forgetting the SSID may help prevent automatic reconnection to that network in the future, but it does not address the immediate need to disconnect from the suspected rogue access point and verify the legitimate hotspot. Disabling all wireless networking permanently is not a practical recommendation in a real support scenario.

  • C. Incorrect.

    This is incorrect because renewing the IP address does not help identify or avoid an evil twin. A rogue access point can still provide DHCP information and appear functional. The issue is not a stale lease; it is that the user may be connected to a malicious wireless network designed to intercept traffic.

  • D. Incorrect.

    This is not the best first action for this situation. Changing the local administrator password may be a good general security practice, but an evil twin attack primarily threatens network traffic and captured credentials entered into fake captive portals or unsecured sessions. The immediate risk is the active connection to the rogue AP, so disconnecting and verifying the network takes priority.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam