Which risk is associated with using an unsecured wireless access point in a public setting during a penetration test?

Prepare for the Penetration Testing and Vulnerability Analysis Test with a range of challenging questions. Study with multiple choice format, hints, and detailed explanations to ace your next exam!

Multiple Choice

Which risk is associated with using an unsecured wireless access point in a public setting during a penetration test?

Explanation:
When a wireless access point is unsecured in a public setting, data transmitted over the air is not protected by encryption, so anyone in range can passively listen to the traffic. This makes it easy for an attacker to eavesdrop on communications and potentially capture credentials, session tokens, or other sensitive information as users connect and send data. The risk isn’t eliminated by user authentication alone—open networks can still expose confidential data if it’s transmitted without protection or if applications don’t use encryption end-to-end. So the most accurate description is that it allows attackers to eavesdrop on traffic and possibly capture credentials. The other statements are incorrect because intercepting data is possible on an open network, attackers can connect to an unsecured network, and there isn’t any mechanism that automatically prevents all compromises.

When a wireless access point is unsecured in a public setting, data transmitted over the air is not protected by encryption, so anyone in range can passively listen to the traffic. This makes it easy for an attacker to eavesdrop on communications and potentially capture credentials, session tokens, or other sensitive information as users connect and send data. The risk isn’t eliminated by user authentication alone—open networks can still expose confidential data if it’s transmitted without protection or if applications don’t use encryption end-to-end.

So the most accurate description is that it allows attackers to eavesdrop on traffic and possibly capture credentials. The other statements are incorrect because intercepting data is possible on an open network, attackers can connect to an unsecured network, and there isn’t any mechanism that automatically prevents all compromises.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy