Drill 3 ยท
AP Cybersecurity Drill 3: Public Wi-Fi and Targeted Smishing is a practice drill. It contains 5 original questions created by Brian Stewart, a Barron's test prep author with over 20 years of tutoring experience.
A customer on coffee-shop Wi-Fi receives a slick scam text and decides how to stay safe; this drill uses an invented company and original figures.
Priya is working from Tindel Roasters and sees two wireless networks:
| Network name | Security |
|---|---|
| Tindel-Guest | Password required (posted at the counter) |
| Tindel Free WiFi | Open, no password |
While deciding, she gets a text:
Hi Priya, this is Tindel Roasters Card Services. We blocked a $240.00 charge on your card. Reply YES to approve or tap tindel-cardalert.com to dispute.
The message uses her first name and the exact shop name and is written in polished, professional language.
A sign at the counter identifies Tindel-Guest as the shop's official guest network.
Question 1. Which of the two visible networks poses the greater risk, and why?
Explanation: Choice D is correct. An open network using a look-alike name may be a rogue access point an attacker set up to intercept traffic, which makes the open Tindel Free WiFi the greater risk. Choice A is incorrect. A posted password on the staffed guest network is normal practice and is more protected than the open network. Choice B is incorrect. Sharing the shop's name does not make a network safe; attackers copy real names on purpose. Choice C is incorrect. Using a phone does not remove the risk of joining an attacker-controlled network.
Question 2. The polished wording, use of Priya's first name, and the exact shop name are most consistent with which description of the text message?
Explanation: Choice B is correct. A scam text aimed at a specific person is smishing, and AI tools can make such messages more polished and personalized, which fits the tailored wording here. Choice A is incorrect. The message demands action on a charge through an outside link, which is not a harmless receipt. Choice C is incorrect. It concerns a card charge, not a network outage, so it is not a carrier notice. Choice D is incorrect. Replying YES to an unverified text is exactly the trap; a real alert can be confirmed through the bank directly.
Question 3. What is the safest immediate way for Priya to handle the text message?
Explanation: Choice A is correct. Even if a charge alert could be real, the safe path is to ignore the message's link and reply path and contact the bank through the number on the card, a channel she knows is genuine. Choice B is incorrect. Replying YES acts on the attacker's instructions and can confirm her number is active. Choice C is incorrect. Tapping the link can lead to a credential-harvesting or malicious page. Choice D is incorrect. Coffee shop staff cannot verify her bank account, so forwarding the text does not help.
Question 4. If Priya connects to the open look-alike network and logs into a site over an unencrypted connection, what is the main risk?
Explanation: Choice C is correct. On an attacker-controlled network, traffic sent without encryption can be read by whoever runs the network, so her login information and other data could be captured. Choice A is incorrect. Slower speed is a performance issue, not the security risk that matters here. Choice B is incorrect. Joining a rogue network does not permanently ban her device from the real one. Choice D is incorrect. The risk is interception by the attacker, not automatic public posting of her history.
Question 5. Which habit would best reduce Priya's risk the next time she works on public Wi-Fi?
Explanation: Choice C is correct. Verifying the correct network name with staff and using a VPN or cellular data for sensitive work protects her even on networks she cannot fully trust. Choice A is incorrect. Signal strength says nothing about whether a network is safe; a rogue network can have a strong signal. Choice B is incorrect. A matching name and a password do not prove a network is the shop's, since names can be copied. Choice D is incorrect. Trusting a network just because the name matches is what the rogue access point relies on.