Domain 4.0 | Network Security — 14% of exam
Learning Objectives
By the end of this lesson, you will be able to:
- Explain rogue DHCP servers and their impact on network traffic
- Describe rogue access points and evil twin attacks
- Explain common social engineering techniques: phishing, dumpster diving, shoulder surfing, and tailgating
- Describe malware as a general attack category
- Recognize appropriate detection approaches for rogue devices and social engineering attempts
Key Terms
| Term | Definition |
|---|---|
| Rogue DHCP Server | An unauthorized DHCP server on a network, handing out incorrect or malicious configuration to unsuspecting clients |
| Rogue Access Point | An unauthorized wireless access point connected to the network, bypassing normal security controls |
| Evil Twin | A rogue access point specifically mimicking a legitimate SSID to trick users into connecting to it |
| Social Engineering | Manipulating people, rather than technology, into revealing information or granting access |
| Malware | A broad term for malicious software, including viruses, worms, ransomware, and trojans |
Explanation
Closing Out Objective 4.2
The previous lesson covered attacks operating largely at the protocol level — DoS, ARP poisoning, DNS poisoning. This final lesson in objective 4.2 covers two different categories: unauthorized devices inserted onto the network, and attacks that target people directly rather than technology at all.Rogue DHCP Servers
A rogue DHCP server is an unauthorized DHCP server that appears on a network — sometimes accidentally (a misconfigured device with DHCP enabled by mistake), sometimes deliberately placed by an attacker — and begins responding to DHCP Discover broadcasts alongside or instead of the legitimate server. Because a DHCP client typically accepts whichever offer arrives first, a rogue server can hand out incorrect configuration — most dangerously, a default gateway or DNS server address pointing to the attacker rather than the legitimate infrastructure.
This achieves a similar practical outcome to ARP poisoning — redirecting a victim’s traffic through the attacker — but through a completely different mechanism, exploiting DHCP’s race-to-respond behavior rather than ARP’s lack of authentication.
Rogue Access Points and Evil Twin
A rogue access point is any unauthorized wireless access point connected to the network, bypassing whatever security controls and configuration standards legitimate access points are expected to follow — a well-meaning employee plugging in a personal wireless router for convenience creates exactly this kind of unmanaged, unmonitored entry point, even without any malicious intent involved.
An evil twin is a specific, more deliberately dangerous variant: a rogue access point set up to broadcast the same SSID as a legitimate network, tricking users’ devices into connecting to it instead of the real one, since most devices simply connect to whichever access point offering a known SSID has the strongest signal. Once a victim connects to the evil twin, all of their traffic flows through the attacker’s access point, providing exactly the kind of positioning an on-path attack depends on — this time achieved through a wireless technique rather than ARP poisoning.
Social Engineering: Exploiting Human Trust
Social engineering targets people rather than technical systems, relying on manipulation, deception, or exploiting normal human helpfulness and trust to achieve the same goals a technical attack might pursue:
Phishing uses fraudulent messages — typically email, but also text messages or other channels — designed to trick a recipient into revealing credentials, clicking a malicious link, or otherwise taking an action that benefits the attacker.
Dumpster diving involves physically searching through discarded materials — trash, recycling — for sensitive information that wasn’t properly destroyed: old printouts, discarded hardware, sticky notes with passwords.
Shoulder surfing means simply observing someone as they enter a password, PIN, or other sensitive information, often in a public or shared space.
Tailgating involves following an authorized person through a secured physical entry point — a locked door, a badge-access turnstile — without independently authenticating, relying on the authorized person’s courtesy (holding the door) or simple inattention. This directly undermines the physical security controls covered earlier in this module, since a lock only enforces access control if each individual is actually required to authenticate through it.
What unites all four techniques is that no technical vulnerability is being exploited at all — the “weakness” being targeted is a human behavior pattern, which means technical controls alone can never fully address social engineering risk. Awareness and training are just as essential a defense here as any firewall or access control system.
Malware: A Brief Overview
Malware is the broad umbrella term for malicious software, covering categories like viruses (which attach to and spread through other programs), worms (which self-propagate across a network without needing a host program), ransomware (which encrypts a victim’s data and demands payment for its release), and trojans (malicious software disguised as something legitimate or desirable). Malware is frequently the payload or end result that a social engineering attack, a rogue device, or another technique is used to deliver in the first place — a phishing email’s malicious link, for instance, is often the delivery mechanism for malware rather than the endpoint attack itself.
Recognition-Level Verification Concepts
A few patterns are worth recognizing on sight:
- Clients receiving incorrect gateway or DNS information from an unexpected DHCP source point to a rogue DHCP server, not a legitimate configuration change.
- A wireless network broadcasting a familiar SSID that isn’t actually the organization’s real access point describes an evil twin attack.
- A fraudulent email urging urgent action or credential entry is phishing; someone physically observing a password being typed is shoulder surfing; someone following an employee through a badge door without their own badge is tailgating.
- Malware is frequently the delivery payload of another attack technique (phishing, a rogue device) rather than a standalone, first-step attack on its own.
Common Exam Traps
- A rogue access point and an evil twin are related but distinct. Every evil twin is a rogue access point, but not every rogue access point is an evil twin — the SSID-mimicking, deliberately deceptive intent is what specifically defines an evil twin.
- Rogue DHCP and ARP poisoning achieve a similar outcome (traffic redirection) through entirely different mechanisms. Don’t conflate the two just because the end result looks similar.
- Social engineering exploits human behavior, not a technical vulnerability — this is exactly why purely technical defenses can’t fully address it, and why user training is a genuinely necessary complementary control.
- Tailgating specifically undermines physical access controls like locks and badge systems — it’s a people-and-process failure, not a technology failure, even though it defeats a technology-enforced control.
- Malware is a broad category, not a single specific attack technique. Don’t treat “malware” as interchangeable with any one specific type like ransomware or a virus — it’s the umbrella term covering all of them.
Lesson 4.2.2 Practice Quiz — Rogue Devices, Evil Twin & Social Engineering
17 questions covering rogue DHCP servers, rogue access points, evil twin attacks, social engineering, and malware.
N10-009 · Domain 4.2Summary
A rogue DHCP server hands out malicious configuration — most dangerously a false gateway or DNS server — achieving traffic redirection through DHCP's race-to-respond behavior rather than ARP manipulation.
A rogue access point is any unauthorized AP on the network; an evil twin is a specific, deliberately deceptive variant mimicking a legitimate SSID to intercept victim traffic.
Social engineering — phishing, dumpster diving, shoulder surfing, and tailgating — targets human behavior directly, meaning technical controls alone can't fully defend against it.
Malware is the broad umbrella term for malicious software, frequently delivered as the payload of a social engineering or rogue-device attack rather than being the initial attack vector itself.
This lesson completes N10-009 objective 4.2 (Types of Attacks and Their Impact) at 2/2 lessons; the next lessons move into objective 4.3, security features and defense techniques.



