N10-009 exam dumps

N10-009 practice question 268 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 268

Single answerRogue devices and services: DHCP, AP, Evil twin, On-path attack

Users in a branch office report that they can connect to a wireless network named CorpWiFi, but after joining, they are redirected to a fake Microsoft 365 login page and some web sessions show certificate warnings. The legitimate CorpWiFi uses WPA2-Enterprise. During troubleshooting, the network administrator discovers a nearby access point broadcasting the same SSID with a stronger signal, and clients connected to it are receiving IP addresses from an unauthorized DHCP service that lists a non-corporate default gateway. Which rogue threat best explains this scenario?

  1. A

    Rogue access point performing an evil twin attack with on-path interception

  2. B

    VLAN hopping attack against the branch switch

  3. C

    DNS amplification attack from an external host

  4. D

    MAC flooding attack causing CAM table exhaustion

Show answer and explanation

Correct answer: A

Explanation

The key indicators are a duplicate SSID, stronger nearby wireless signal, users associating to the wrong AP, and rogue DHCP leases providing an attacker-controlled default gateway. Together, these point to an evil twin attack delivered through a rogue AP. Because the attacker is also influencing Layer 3 settings and users see fake login prompts and certificate warnings, the attack is facilitating on-path interception and credential theft. In real environments, mitigation includes using WPA2/WPA3-Enterprise with certificate validation, deploying wireless intrusion detection/prevention, disabling client auto-join where appropriate, monitoring for unauthorized SSIDs/BSSIDs, and using DHCP snooping plus network access controls on the wired side to prevent unauthorized DHCP services. These practices align with common enterprise wireless security guidance and Network+ objectives covering rogue devices, evil twins, DHCP attacks, and on-path attacks.

  • A. Correct.

    Correct. This is the best match for the evidence. An evil twin is a malicious wireless access point configured to imitate a legitimate SSID so users connect to it instead of the real network. The stronger signal and duplicated SSID are classic indicators. The unauthorized DHCP service handing out a different default gateway suggests the attacker is controlling client network settings to route traffic through their device, enabling on-path interception. The fake login page and certificate warnings further support credential harvesting and traffic interception.

  • B. Incorrect.

    Incorrect. VLAN hopping is a Layer 2 attack used to gain access to traffic on other VLANs, typically through switch misconfiguration such as improper trunking or double-tagging. It does not fit the wireless symptoms here, such as a duplicate SSID, stronger rogue signal, fake captive-style login page, and unauthorized DHCP leases from a nearby access point.

  • C. Incorrect.

    Incorrect. DNS amplification is a volumetric DDoS technique that abuses open resolvers to overwhelm a target with traffic. It is not a method for luring nearby wireless clients onto a fake SSID or assigning them rogue DHCP settings. Someone might choose this because users are being redirected, but the scenario points to local wireless impersonation and traffic interception rather than a distributed denial-of-service event.

  • D. Incorrect.

    Incorrect. MAC flooding attempts to overflow a switch's CAM table so the switch begins flooding frames, potentially allowing sniffing on a wired segment. While that can aid eavesdropping in some environments, it does not explain the duplicate wireless network name, stronger nearby access point, fake login page, or rogue DHCP service issuing non-corporate gateway information.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam