An assessor studies a rogue Enterprise AP concept that presents a familiar municipal SSID. What attack surface does that scenario primarily define?
Select an answer to reveal the explanation.
Short Explanation
Think of a look-alike city Wi-Fi sign that funnels staff into the wrong authentication desk. A rogue Enterprise AP with a familiar SSID is about stealing or intermediating 802.1X/EAP toward attacker-controlled AAA—not about PSK handshake cracking or Bluetooth pairing.
Full Explanation
A rogue Enterprise access point that advertises a trusted municipal SSID defines an evil-twin surface aimed at 802.1X clients. Users who associate may begin EAP toward AAA infrastructure the assessor controls in an authorized lab, which is a different problem class than Personal PSK handshake capture, captive-portal HTTPS quirks, or Bluetooth. The finding centers on impersonation of Enterprise identity and credential exposure risk when clients do not strictly validate the authenticating server.