Evil twin attack
A wireless attack in which a malicious access point impersonates a legitimate network's name so that users connect to it, placing the attacker in the path of their traffic.
An evil twin is an attacker’s access point set up to look like a network users already trust, broadcasting the same SSID and often a stronger signal nearby. Devices may join automatically, and an attacker may send deauthentication frames to push users off the real network. Once connected, the victim’s traffic passes through the attacker, which is a wireless form of man-in-the-middle attack. A fake captive portal is a common way to harvest credentials.
It is commonly confused with a rogue access point. A rogue access point is an unauthorised access point connected to the organisation’s own network, opening a back door into it. An evil twin need not touch the corporate network at all; it targets the users by imitating a trusted network. The defences follow from the difference. Authentication that proves the network to the client, such as EAP-TLS with server certificate validation under WPA2-Enterprise or WPA3-Enterprise, lets devices reject the impostor. A VPN or end-to-end TLS limits what an attacker in the path can read.
Exam relevance: a scenario is likely to describe users seeing a familiar network name in a public place and then losing credentials. Candidates are expected to separate the evil twin, which imitates a network, from the rogue access point, which extends one without permission.