220-1102 exam dumps

220-1102 practice question 446 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 446

Single answerOn-path attack

Users at a small office report that they can reach websites, but several employees receive browser warnings that the company payroll site has an invalid certificate when connected to the guest Wi-Fi. The same site works normally from the wired network. A technician discovers a rogue wireless access point using the same SSID as the guest network and forwarding traffic to the internet. Which attack best explains this behavior?

  1. A

    On-path attack using a malicious access point to intercept traffic

  2. B

    Denial-of-service attack preventing users from reaching the payroll site

  3. C

    Ransomware encrypting browser certificate stores on employee laptops

  4. D

    Password spraying attack against employee payroll accounts

Show answer and explanation

Correct answer: A

Explanation

The most likely cause is an on-path attack conducted through a rogue or evil twin wireless access point. In real environments, attackers may clone an SSID and place themselves between the victim and the internet to capture or alter traffic. One of the practical indicators is unexpected certificate warnings on HTTPS sites, especially when the issue occurs only on a specific network. Best practices include verifying the legitimate SSID and security settings, removing rogue APs, using WPA2/WPA3 with strong authentication, training users to avoid certificate warnings, and enforcing HTTPS with valid certificates. This aligns with common security guidance from organizations such as NIST, which emphasizes certificate validation, secure wireless configuration, and protection against adversary-in-the-middle attacks.

  • A. Correct.

    Correct. This is a classic on-path attack scenario, sometimes called a machine-in-the-middle or adversary-in-the-middle attack. A rogue access point with the same SSID can trick users into connecting through it, allowing the attacker to inspect, redirect, or tamper with traffic. Certificate warnings are a common sign when the attacker attempts HTTPS interception or presents an untrusted certificate.

  • B. Incorrect.

    Incorrect. A denial-of-service attack is intended to disrupt availability, typically making a service slow or unreachable. In this scenario, users can still browse sites, and the main symptom is certificate warnings on one network segment, which points to interception or tampering rather than service exhaustion.

  • C. Incorrect.

    Incorrect. Ransomware focuses on encrypting files or locking systems to demand payment. It would not typically cause a payroll website to show certificate warnings only when users connect through a specific wireless network. The network-specific behavior strongly suggests traffic interception.

  • D. Incorrect.

    Incorrect. Password spraying is an authentication attack that tries a small number of common passwords against many accounts. It targets credentials, not encrypted web sessions in transit. It does not explain why certificate errors occur only on the guest Wi-Fi.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam