Network Security 14% Lesson 6 of 8

Lesson 4.2.2 — Rogue Devices, Evil Twin & Social Engineering

Avatar Of Asad IjazAsad Ijaz ·Sep 20, 2026 ·5 min read
75% through domain
Illustration Of A Convincing Mask Hovering In Front Of A Plain Face, Representing Deception And Impersonation

Domain 4.0 | Network Security — 14% of exam

Learning Objectives

By the end of this lesson, you will be able to:

  • Explain rogue DHCP servers and their impact on network traffic
  • Describe rogue access points and evil twin attacks
  • Explain common social engineering techniques: phishing, dumpster diving, shoulder surfing, and tailgating
  • Describe malware as a general attack category
  • Recognize appropriate detection approaches for rogue devices and social engineering attempts

Key Terms

TermDefinition
Rogue DHCP ServerAn unauthorized DHCP server on a network, handing out incorrect or malicious configuration to unsuspecting clients
Rogue Access PointAn unauthorized wireless access point connected to the network, bypassing normal security controls
Evil TwinA rogue access point specifically mimicking a legitimate SSID to trick users into connecting to it
Social EngineeringManipulating people, rather than technology, into revealing information or granting access
MalwareA broad term for malicious software, including viruses, worms, ransomware, and trojans

Explanation

Closing Out Objective 4.2

The previous lesson covered attacks operating largely at the protocol level — DoS, ARP poisoning, DNS poisoning. This final lesson in objective 4.2 covers two different categories: unauthorized devices inserted onto the network, and attacks that target people directly rather than technology at all.

Rogue DHCP Servers

A rogue DHCP server is an unauthorized DHCP server that appears on a network — sometimes accidentally (a misconfigured device with DHCP enabled by mistake), sometimes deliberately placed by an attacker — and begins responding to DHCP Discover broadcasts alongside or instead of the legitimate server. Because a DHCP client typically accepts whichever offer arrives first, a rogue server can hand out incorrect configuration — most dangerously, a default gateway or DNS server address pointing to the attacker rather than the legitimate infrastructure.
Diagram Showing A Client Accepting A Malicious Dhcp Offer From A Rogue Server Instead Of The Authorized Server, Redirecting Its Gateway
How A Rogue Dhcp Server Can Redirect A Client’S Traffic By Issuing A Malicious Default Gateway

This achieves a similar practical outcome to ARP poisoning — redirecting a victim’s traffic through the attacker — but through a completely different mechanism, exploiting DHCP’s race-to-respond behavior rather than ARP’s lack of authentication.

Rogue Access Points and Evil Twin

A rogue access point is any unauthorized wireless access point connected to the network, bypassing whatever security controls and configuration standards legitimate access points are expected to follow — a well-meaning employee plugging in a personal wireless router for convenience creates exactly this kind of unmanaged, unmonitored entry point, even without any malicious intent involved.

An evil twin is a specific, more deliberately dangerous variant: a rogue access point set up to broadcast the same SSID as a legitimate network, tricking users’ devices into connecting to it instead of the real one, since most devices simply connect to whichever access point offering a known SSID has the strongest signal. Once a victim connects to the evil twin, all of their traffic flows through the attacker’s access point, providing exactly the kind of positioning an on-path attack depends on — this time achieved through a wireless technique rather than ARP poisoning.
Diagram Showing A Client Connecting To A Stronger-Signal Attacker Access Point Broadcasting The Same Ssid As The Legitimate Network
How An Evil Twin Access Point Mimics A Legitimate Ssid To Intercept Victim Traffic

Social Engineering: Exploiting Human Trust

Social engineering targets people rather than technical systems, relying on manipulation, deception, or exploiting normal human helpfulness and trust to achieve the same goals a technical attack might pursue:

Phishing uses fraudulent messages — typically email, but also text messages or other channels — designed to trick a recipient into revealing credentials, clicking a malicious link, or otherwise taking an action that benefits the attacker.

Dumpster diving involves physically searching through discarded materials — trash, recycling — for sensitive information that wasn’t properly destroyed: old printouts, discarded hardware, sticky notes with passwords.

Shoulder surfing means simply observing someone as they enter a password, PIN, or other sensitive information, often in a public or shared space.

Tailgating involves following an authorized person through a secured physical entry point — a locked door, a badge-access turnstile — without independently authenticating, relying on the authorized person’s courtesy (holding the door) or simple inattention. This directly undermines the physical security controls covered earlier in this module, since a lock only enforces access control if each individual is actually required to authenticate through it.
Diagram Showing Four Social Engineering Techniques: Phishing, Dumpster Diving, Shoulder Surfing, And Tailgating
How Phishing, Dumpster Diving, Shoulder Surfing, And Tailgating Each Exploit Human Behavior Differently

What unites all four techniques is that no technical vulnerability is being exploited at all — the “weakness” being targeted is a human behavior pattern, which means technical controls alone can never fully address social engineering risk. Awareness and training are just as essential a defense here as any firewall or access control system.

Malware: A Brief Overview

Malware is the broad umbrella term for malicious software, covering categories like viruses (which attach to and spread through other programs), worms (which self-propagate across a network without needing a host program), ransomware (which encrypts a victim’s data and demands payment for its release), and trojans (malicious software disguised as something legitimate or desirable). Malware is frequently the payload or end result that a social engineering attack, a rogue device, or another technique is used to deliver in the first place — a phishing email’s malicious link, for instance, is often the delivery mechanism for malware rather than the endpoint attack itself.

Recognition-Level Verification Concepts

A few patterns are worth recognizing on sight:

  • Clients receiving incorrect gateway or DNS information from an unexpected DHCP source point to a rogue DHCP server, not a legitimate configuration change.
  • A wireless network broadcasting a familiar SSID that isn’t actually the organization’s real access point describes an evil twin attack.
  • A fraudulent email urging urgent action or credential entry is phishing; someone physically observing a password being typed is shoulder surfing; someone following an employee through a badge door without their own badge is tailgating.
  • Malware is frequently the delivery payload of another attack technique (phishing, a rogue device) rather than a standalone, first-step attack on its own.

Common Exam Traps

  • A rogue access point and an evil twin are related but distinct. Every evil twin is a rogue access point, but not every rogue access point is an evil twin — the SSID-mimicking, deliberately deceptive intent is what specifically defines an evil twin.
  • Rogue DHCP and ARP poisoning achieve a similar outcome (traffic redirection) through entirely different mechanisms. Don’t conflate the two just because the end result looks similar.
  • Social engineering exploits human behavior, not a technical vulnerability — this is exactly why purely technical defenses can’t fully address it, and why user training is a genuinely necessary complementary control.
  • Tailgating specifically undermines physical access controls like locks and badge systems — it’s a people-and-process failure, not a technology failure, even though it defeats a technology-enforced control.
  • Malware is a broad category, not a single specific attack technique. Don’t treat “malware” as interchangeable with any one specific type like ransomware or a virus — it’s the umbrella term covering all of them.

Lesson 4.2.2 Practice Quiz — Rogue Devices, Evil Twin & Social Engineering

17 questions covering rogue DHCP servers, rogue access points, evil twin attacks, social engineering, and malware.

N10-009 · Domain 4.2
Question 1Plain
What is a rogue DHCP server?
A rogue DHCP server is an unauthorized server handing out incorrect or malicious configuration, such as a false gateway or DNS server.
Question 2Plain
What is an evil twin?
An evil twin is a rogue access point specifically designed to mimic a legitimate SSID, tricking victims into connecting to the attacker instead.
Question 3Plain
What is malware?
Malware is the broad umbrella term covering many categories of malicious software, including viruses, worms, ransomware, and trojans.
Question 4Choose Two
Which two statements about rogue access points and evil twins are correct? (Choose two.)
Every evil twin is a rogue AP, but not every rogue AP mimics an SSID — that deliberate SSID-mimicking is exactly what makes an evil twin a specific, more dangerous subtype.
Question 5Choose Two
Which two statements about social engineering are correct? (Choose two.)
Social engineering targets human behavior specifically, encompassing techniques like phishing, tailgating, shoulder surfing, and dumpster diving — it is not purely technical, and it's not limited to malware delivery alone.
Question 6Choose Two
Which two statements about rogue DHCP servers are correct? (Choose two.)
Rogue DHCP servers redirect traffic by handing out false configuration, exploiting the fact that clients accept whichever offer arrives first — a completely different mechanism from ARP spoofing, and not the same as a legitimate, coordinated DHCP failover setup.
Question 7Scenario
An employee's laptop receives a default gateway address that doesn't match the legitimate network's gateway, coming from an unexpected source on the network. What is most likely occurring?
An unexpected source handing out an incorrect gateway address is exactly the signature of a rogue DHCP server.
Question 8Scenario
A user connects to what appears to be the company's Wi-Fi network, using the familiar SSID, but it's actually being broadcast by an attacker's access point. What attack is this?
An access point broadcasting a familiar SSID that isn't actually the legitimate network is exactly an evil twin.
Question 9Scenario
An employee receives an urgent-sounding email claiming their account will be suspended unless they click a link and enter their password immediately. What technique is this?
A fraudulent, urgency-driven email trying to trick the recipient into revealing credentials is a textbook phishing attempt.
Question 10Scenario
An unauthorized individual follows an employee through a badge-secured door without swiping their own badge, relying on the employee holding the door open. What technique is this?
Following an authorized person through a secured entry point without independently authenticating is exactly tailgating.
Question 11Scenario
An attacker searches through a company's discarded trash and recovers printed documents containing sensitive account information. What technique is this?
Physically searching discarded materials for sensitive information is exactly dumpster diving.
Question 12Exhibit
Based on this DHCP log, what is the concern?
DHCP Log: Client Discover broadcast received offers from: Server A (10.0.0.5, authorized) — Gateway: 10.0.0.1 Server B (10.0.0.199, NOT in authorized server list) — Gateway: 10.0.0.250 Client accepted offer from: Server B
Server B is not in the authorized server list and handed out a different gateway that the client accepted — exactly a rogue DHCP server scenario.
Question 13Exhibit
Based on this wireless scan, what is the concern?
Wireless Scan Results: SSID: "CorpNet-WiFi", BSSID: 00:11:22:AA:BB:CC, Signal: -45dBm (known legitimate AP) SSID: "CorpNet-WiFi", BSSID: 66:77:88:DD:EE:FF, Signal: -30dBm (unrecognized BSSID, stronger signal)
Two access points broadcasting the identical SSID, but with a second, unrecognized BSSID offering a stronger signal, is a strong evil twin indicator.
Question 14Exhibit
Based on this email sample, what technique does it represent?
Email Subject: URGENT: Your account will be suspended in 24 hours Body: Click here immediately to verify your password and avoid suspension: [suspicious-link] Sender: "IT-Support"
Urgency, a suspicious link, and a request to enter a password are all classic phishing indicators.
Question 15Exhibit
Based on this security camera log, what technique was observed?
Camera Log — Badge Door, Building A 10:15:02 — Employee badges in, door opens 10:15:04 — Second individual enters through same open door, no badge swipe recorded
A second individual entering through a badge door with no independent badge swipe is exactly tailgating.
Question 16Exhibit
Based on this incident report, what technique was used to obtain the information?
Incident Report: Discovery: Printed customer account statements found in unsecured dumpster behind office building Documents: Not shredded, contained full account numbers
Unshredded sensitive documents recovered from an unsecured dumpster is exactly dumpster diving in action.
Question 17Exhibit
Based on this analysis, what category of attack does this represent?
Malware Analysis Report: Sample: encrypts user files with AES-256 Behavior: Displays ransom note demanding payment for decryption key Classification: Ransomware
Ransomware encrypting files and demanding payment is a specific, well-known category of malware — the broader umbrella term covering this and other malicious software types.
📝

Summary

A rogue DHCP server hands out malicious configuration — most dangerously a false gateway or DNS server — achieving traffic redirection through DHCP's race-to-respond behavior rather than ARP manipulation.

A rogue access point is any unauthorized AP on the network; an evil twin is a specific, deliberately deceptive variant mimicking a legitimate SSID to intercept victim traffic.

Social engineering — phishing, dumpster diving, shoulder surfing, and tailgating — targets human behavior directly, meaning technical controls alone can't fully defend against it.

Malware is the broad umbrella term for malicious software, frequently delivered as the payload of a social engineering or rogue-device attack rather than being the initial attack vector itself.

This lesson completes N10-009 objective 4.2 (Types of Attacks and Their Impact) at 2/2 lessons; the next lessons move into objective 4.3, security features and defense techniques.

Avatar Of Asad Ijaz

Lead Networking Architect and Editor at NetworkUstad. BS in Computer Networks and Security, CCNP and CCNA certified, with 11+ years of experience in enterprise network design, implementation, and troubleshooting. Writes practical tutorials on routing, IPv4 management, network automation, and security fundamentals.