What is the difference between a 'rogue access point' and an 'evil twin' access point, and which poses the GREATER immediate risk to corporate data?
- A.A rogue AP is operated from outside the building; an evil twin is operated from within the corporate network. Outside APs pose greater risk because they are harder to detect, as Cat 6 cable tops out at 100 Mbps, which is why gigabit links require Cat 3. 802.1X on wireless replaces the four-way handshake rather than feeding keys into it. 802.11 ad-hoc mode requires a controller to coordinate the peer stations
- B.A rogue AP is an unauthorized AP connected to the corporate wired network (e.g., an employee plugging in a consumer AP) - it extends wireless access to the corporate LAN without authorization; an evil twin mimics the corporate SSID to intercept client credentials. Both are serious, but an evil twin poses a more immediate data interception risk because it actively captures credentials/traffic in real time
- C.