Identifying Unknown Wi-Fi Signals as Rogue Access Points

Answer Correct answer: C — The presence of Wi-Fi signals from an unknown device indicates a rogue access point connected to the network.

During a wireless network scan at a data center the IT security team discovered Wi-Fi signals broadcasting from an unknown device. Which of the following best describes the cause of the incident?

  1. Domain hijacking
  2. On-path attack
  3. Rogue access point Correct Answer
  4. Jamming

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests recognition of physical layer security threats; the trap is confusing signal presence with protocol attacks like on-path or jamming.

Discovering unauthorized wireless signals indicates a rogue access point. This scenario highlights the risk of unapproved devices connecting to corporate networks.

Candidates often select 'On-path attack' assuming interception, but without evidence of traffic redirection, an unknown device is simply a rogue AP.

Community Discussion (4 comments)

CircaG 👍 6 Selected: C
C. Rogue Access Point. If there are Wi-Fi signals coming from an unknown device, that is a rogue access point.
russian 👍 3 Selected: C
toddler question
MortG7 👍 1
C. Rogue access point
Gabuu 👍 1 Selected: C
Rogue access point

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The discovery of Wi-Fi signals from an unknown device is the definitive indicator of a rogue access point. A rogue AP is any wireless access point that has been added to a network without explicit authorization from the system administrator. This creates a significant security vulnerability as it can bypass perimeter defenses.

Why the Other Options Are Wrong

Domain hijacking (A) involves taking control of a domain name registration and is unrelated to physical hardware signals. An on-path attack (B) refers to man-in-the-middle interceptions which require active traffic manipulation, not just the presence of a signal. Jamming (D) involves disrupting communications by flooding frequencies, which would likely cause connectivity loss rather than broadcasting identifiable signals.

Community Comment Notes

The community consensus overwhelmingly supports option C, with users describing it as a straightforward identification question. As CircaG noted, the key phrase "unknown device" directly maps to the definition of a rogue access point in certification contexts.

Exam Strategy

Always associate 'unknown' or 'unauthorized' hardware with physical security risks like rogue devices before considering complex logical attacks.

Frequently Asked Questions

How does a rogue access point differ from an evil twin?

A rogue AP is unauthorized hardware added to the network, while an evil twin mimics a legitimate SSID to trick users into connecting.

Can jamming be detected by scanning for Wi-Fi signals?

No, jamming disrupts signals so they cannot be received or scanned properly, whereas rogue APs broadcast clear, usable signals.

Related Analysis

← Back to SY0-601 Study Guide