Identifying Rogue Access Points Bypassing Content Filters

Answer Correct answer: B — A rogue access point is allowing users to bypass controls.

A business uses Wi-Fi with content filtering enabled. An employee noticed a coworker accessed a blocked site from a work computer and reported the issue. While investigating the issue, a security administrator found another device providing internet access to certain employees. Which of the following best describes the security risk?

  1. The host-based security agent is not running on all computers.
  2. A rogue access point is allowing users to bypass controls. Correct Answer
  3. Employees who have certain credentials are using a hidden SSID.
  4. A valid access point is being jammed to limit availability.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests recognition of rogue APs by correlating 'another device' with 'bypassed content filtering'. The trap is assuming legitimate infrastructure (Option C).

This question addresses the risk of unauthorized wireless devices bypassing corporate security controls. The correct answer identifies a rogue access point as the source of unfiltered internet access.

Learners often choose Option C, focusing on 'certain employees' and 'hidden SSID', missing the critical fact that the device is providing external internet access outside the controlled network.

Community Discussion (5 comments)

1403ad2 👍 8 Selected: B
choose b 2024-20-2 On Test and passed with 802
Hs1208 👍 6 Selected: B
B. A rogue access point is allowing users to bypass controls.
LayinCable 👍 1 Selected: B
A and B are the two most plausible answers. But A is kind of vague on purpose to get ya, if a business has clients throughout, then I'm more than sure that the security/IT dept. has host-based security on all of the workstations. THEREFORE, making 'B' the shining star through logic.
DrZoidBergsClaws 👍 4
The answer is B. Read the question it says "a security administrator found another device providing internet access to certain employees". Thats a rogue access point.
Baba111222 👍 2 Selected: C
Going with C on that one. SSID can be easily hidden and allow only users knowing the SSID and pwd to connect to it. Note that only "certain" employees access the second device. It does not look like an incident, rather someone tired of the filter wanting to access blocked content.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The scenario describes a device providing internet access to employees that circumvents the business's content filtering. This is the definition of a rogue access point (Rogue AP), which allows users to bypass perimeter security controls like firewalls and web filters. The presence of this unauthorized device creates a direct security risk by exposing the network to unmonitored traffic.

Why the Other Options Are Wrong

Option A is incorrect because host-based agents do not control network-level routing or provide alternative internet paths. Option C is incorrect because using a hidden SSID does not inherently bypass content filtering unless the device itself is an unauthorized gateway (which makes it a Rogue AP anyway). Option D is incorrect because jamming affects availability (DoS) rather than enabling bypassed access; jamming would prevent connection, not facilitate it.

Community Comment Notes

The community overwhelmingly supports Option B. As user DrZoidBergsClaws noted, the key phrase is "a security administrator found another device providing internet access," which directly points to a rogue AP. User LayinCable also reasoned that Option A is too vague compared to the specific threat of bypassed controls described in Option B.

Official Reference

Exam Strategy

When you see keywords like 'unauthorized device,' 'providing internet access,' or 'bypassing controls' in a wireless context, immediately consider Rogue APs. Always distinguish between authentication methods (SSID/credentials) and actual network access control mechanisms.

Frequently Asked Questions

Why isn't Option C (Hidden SSID) the answer?

Hiding an SSID is a security measure, but it doesn't explain how the device provides internet access outside the corporate filter. The core issue is the unauthorized network bridge.

Does a rogue AP always bypass content filtering?

Yes, if it connects directly to the internet (e.g., via cellular or home broadband) without passing through the corporate firewall, it bypasses all content filtering rules.

Related Analysis

← Back to SY0-601 Study Guide