You are a threat analyst. Four wireless attack specimens have been flagged for investigation. Dissect each one: identify the attack type, adversary skill level, what was stolen/disrupted, and the specific control that would have prevented it.
Each specimen is a documented wireless attack incident. Analyze with AP exam rigor: attack type, adversary skill level, impact, and the specific control that would have prevented it. Each specimen is worth 6 points.
Specimen 1 — Introductory
Coffee Shop Evil Twin
6 pts
A college student arrives at a coffee shop and connects to “CafeNova_WiFi” (the real network is “CafeNova-Guest”). The student logs into their university email and their streaming service. Twenty minutes later they are locked out of both accounts. Another patron notices a laptop in a corner with a portable router and unusual software running.
Attack type:
Adversary skill level:
Primary impact (what was stolen or disrupted):
Control that would have prevented the harm:
Specimen 2 — Moderate
Hospital Communications Disruption
6 pts
During a hospital’s emergency response drill, all wireless devices in the east wing stop functioning simultaneously for 90 minutes. Nurses cannot communicate via wireless pagers, the wireless medication dispensing system goes offline, and patient monitoring devices lose their wireless connection. When security investigates, they find a device in a maintenance closet emitting EM signals in the 2.4 GHz frequency band. No patient data was accessed or stolen.
Attack type:
Adversary skill level:
Primary impact (what was stolen or disrupted):
Control that would have prevented the harm:
Specimen 3 — Challenging
Multi-Stage War Driving to Evil Twin
6 pts
A threat intelligence team identifies a pattern: over three weeks, the same vehicle was observed parked outside six financial services firms with a wireless scanning device running. Two weeks later, three of those firms reported employees connecting to evil twins in their parking structures. The evil twins used SSIDs identical to each firm’s legitimate guest network, broadcast from devices physically placed inside the parking structures. Employee credentials and session tokens were captured.
Attack type:
Adversary skill level:
Primary impact (what was stolen or disrupted):
Control that would have prevented the harm:
Specimen 4 — Expert
Coordinated Signal Leakage Exploitation
6 pts
A security researcher hired to assess a hospital campus discovers: (1) the hospital’s internal clinical network signal is detectable from the adjacent public park, (2) the hospital’s SSID is being broadcast by two devices in the park (not the hospital’s own WAPs), and (3) three employees had recently connected to what they thought was the hospital’s guest network from the park during lunch. Their session tokens for the clinical records system were later used to access records from an IP outside the hospital. The attack involved both passive reconnaissance and active exploitation.
Attack type:
Adversary skill level:
Primary impact (what was stolen or disrupted):
Control that would have prevented the harm:
0 / 24 pts
✎ AP Exam Tip
The hardest Topic 1.3 AP exam questions combine two attack types in one scenario (war driving enabling evil twin). The key distinction: war driving is ALWAYS passive/recon (no active attack, no data stolen), evil twin is ALWAYS active (MITM, credentials at risk). Jamming is ALWAYS DoS only (no data stolen). Low-skilled adversaries use pre-built tools for all three. VPN defeats evil twin credential theft but cannot prevent jamming (physical signal disruption). Signal power reduction defeats war driving-enabled evil twins by eliminating external attack surface.
Whether you're a student, parent, or teacher — I'd love to hear from you.
Just want free AP CS resources?
Enter your email below and check the subscribe box — no message needed.
Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.
Typically responds within 24 hours
✓
Message Sent!
Thanks for reaching out. I'll get back to you within 24 hours.
34.8% of Tanner’s CSP students score 5s. The national average is 9.6%.
I’m a Student
I’m a Teacher
✓Free AP CSP Big Ideas cheat sheet (PDF)
✓Daily practice questions covering all 5 Big Ideas
✓Create Task tips that actually work — from a real AP teacher
✓Free class codes with student progress tracking
✓3 full practice exams + Top 100 questions for your class
✓Create Task guidance and pseudocode reference sheets
Which AP CS exams are you prepping for?
✓
You’re in!
Your Big Ideas cheat sheet is on its way.
No thanks, I’ll figure it out myself
Avg student improvement: 2+ score levels | Real AP teacher, not just a tutor
AP Cybersecurity — National Launch 2026–27
Get Early Access to AP Cyber
AP Cyber launches nationally fall 2026. Get in early to help shape the course — start free with Unit 1 and the free teacher gradebook.
✓
You’re in — you’re on the AP Cyber early-access list!
Tanner will follow up personally within 48 hours. Your feedback will directly shape what gets built.
Step 1 of 4
Early Access — Limited Spots
Who are you?
Are you a teacher or a student?
I’m a Teacher
I’m a Student
Free to start — Unit 1 and the teacher gradebook are always free, no credit card.
Founding teachers unlock all 5 units and get direct input on what we build.
Not interested right now
Step 2 of 4
Your School
Tell us about your class
Other AP CS courses you teach
Your Situation
Tell us about yourself
Step 3 of 4
Classroom Needs
What does your classroom need? (select all that apply)
How You Study
What would help you most? (select all that apply)
Step 4 of 4
Almost Done
Where should we send your early-access details?
Free gradebook + Unit 1 | Your feedback shapes the course | Built by a real AP teacher