What is the difference between a 'rogue access point' and an 'evil twin' access point, and which poses the GREATER immediate risk to corporate data?
- A.A rogue AP is an unauthorized AP connected to the corporate wired network (e.g., an employee plugging in a consumer AP) - it extends wireless access to the corporate LAN without authorization; an evil twin mimics the corporate SSID to intercept client credentials. Both are serious, but an evil twin poses a more immediate data interception risk because it actively captures credentials/traffic in real time
- B.A rogue AP uses WEP encryption which is cracked within minutes; an evil twin uses WPA2 encryption, making it more dangerous because its traffic is harder to decrypt
- C.A rogue AP and evil twin are identical threats - both are unauthorized APs broadcasting the corporate SSID on the same channel