A student claims HTTPS captive portals cannot be spoofed on a rogue network the assessor fully controls. What nuance about trust on that path is most accurate?
Select an answer to reveal the explanation.
Short Explanation
If you own the AP and the DNS the client hears, you can steer them to a portal you built—HTTPS lock icons and scary warnings still need a human who pays attention. Control of the path matters; it is not magic immunity, CA-token theft as a prerequisite story, or a fiber-only myth.
Full Explanation
On a rogue path the assessor operates, DNS and HTTP(S) landing content can be controlled or influenced, so users may be presented with attacker-operated portal pages. Browser TLS helps when users heed certificate validation, but it does not make spoofed portals conceptually impossible. Ownership of the city's CA tokens is not required for the class, and captive portals absolutely appear on Wi-Fi.