An insider at a municipal court annex runs a soft AP on a laptop that bridges the guest SSID segment onto the staff VLAN. Which attack path does this primarily represent?
Select an answer to reveal the explanation.
Short Explanation
That laptop soft AP is a secret tunnel from the lobby Wi-Fi into the clerk network—an insider building a bridge where policy said “wall.” Guest isolation dies the moment someone splices the VLANs together. This is not a harmless spectrum walk.
Full Explanation
Insider-facilitated soft APs or unauthorized bridges can defeat guest/staff segmentation by forwarding traffic across security zones. The attack path combines wireless and wired policy failure and is a recognized WLAN threat pattern beyond external RF-only adversaries. Detection often relies on WIDS/WIPS sensors and network monitoring for unexpected bridging or ad-hoc APs.