Case Files: Public Network Security AP Cybersecurity · Unit 1 · Topic 1.3
0 / 0 answered

Investigator Briefing

Topic 1.3 · Best Practices for Public Networks

You've been assigned four incident files, each involving a device connecting to a network outside the safety of a trusted, private connection. Public Wi-Fi is convenient — and that convenience is exactly what attackers count on. Your job is to read each case, examine the evidence, and answer the investigator's questions in your own words.

Essential Question: What risks are associated with public Wi-Fi, and how can users reduce those risks?
Evil Twin Attack — fraudulent network imitating a legitimate one
Jamming Attack — disrupts wireless comms by flooding frequencies
War Driving — searching for/mapping wireless networks while traveling
VPN — encrypts traffic between a device and a VPN provider
SSID — the name identifying a wireless network
Denial of Service (DoS) — prevents authorized access to a service/network
Wireless Access Point (WAP) — device providing wireless connectivity
CASE 2027-1.3A
Evil Twin Attack

The Contested Connection

Location: Grindhouse Coffee, Downtown · Reported by: Maya Ontiveros, patron

Maya sits down at her usual table at Grindhouse Coffee, opens her laptop, and clicks the Wi-Fi icon. Two networks with similar names show up in the list — more than she remembers seeing here before. She's in a hurry to submit an assignment before it's due, so she just wants to pick one and get online.

A hand-written sign taped to the counter reads: "Free Wi-Fi: ask barista for password." Maya didn't ask — she just tapped a name that looked right.

Click a row below to flag any network(s) you find suspicious.
FlagSSID (Network Name)SignalSecurityFirst SeenNotes
Grindhouse_Coffee_Guest-52 dBmWPA2 (password on receipt)Known — posted for monthsMatches the shop's printed menu board
Grindhouse Coffee Free WiFi-41 dBm (strongest)Open — no passwordFirst appeared ~10 min agoSlightly different spacing/name than the shop's real network
Grindhouse_Coffee_Guest_5G-60 dBmWPA2 (password on receipt)Known — posted for months5GHz band of the same trusted network
xfinitywifi-70 dBmOpen — captive portalKnown — citywide hotspotUnrelated public hotspot, weak signal from outside
CASE 2027-1.3B
Jamming / Denial of Service

Silence at Gate 12

Location: Terminal B, Gate 12 · Reported by: Airport IT Operations

At 9:14 a.m., travelers waiting to board at Gate 12 begin complaining that their phones and laptops suddenly drop off the terminal Wi-Fi at the same moment. Bluetooth headphones disconnect. Mobile boarding passes won't load. The disruption lasts about a minute before the network snaps back to normal, right as boarding begins.

Airport IT pulls the wireless monitoring log for the gate's access point covering that window.

Click the log rows that show evidence of the disruption.
FlagTimeConnected DevicesRF Noise FloorStatus
09:12:10119-95 dBmNormal operation
09:13:58121-94 dBmNormal operation
09:14:476-41 dBmSharp RF noise spike; mass disconnect
09:15:100-38 dBmNo client traffic; channel saturated
09:15:520-40 dBmNo client traffic; channel saturated
09:19:55123-94 dBmNoise floor returns to baseline; devices reconnect
CASE 2027-1.3C
War Driving

The War Driving Notebook

Location: Oakwood Residential District · Reported by: Neighborhood watch, Block Captain D. Reyes

For the past week, a resident has noticed the same gray sedan slow-rolling through the neighborhood at odd hours, idling briefly on each block before moving on. After a break-in attempt at a house whose Wi-Fi router still used its factory default password, police recover a laptop and a spiral notebook from a suspect's vehicle. The laptop's wireless scanning history is pulled as evidence.

Click the entries that suggest the driver was scanning and mapping networks rather than just using Wi-Fi normally.
FlagTimeBlockSSID DetectedSignalEncryptionDwell Time
20:03Oak St, 100 blockHomeNet_2G-55 dBmWPA240 sec
20:03Oak St, 100 blockLinksys00421-60 dBmNone (open)40 sec
20:04Oak St, 100 blockATT-9F3D-58 dBmWPA240 sec
20:11Maple Ave, 200 blockNETGEAR22-50 dBmWEP35 sec
20:11Maple Ave, 200 blockFBI Surveillance Van 2-64 dBmWPA235 sec
20:18Birch Ln, 300 blockReyes_Family_Wifi-45 dBmWPA332 sec
20:47Birch Ln, 300 block (parked in driveway)Reyes_Family_Wifi-30 dBmWPA326 min
CASE 2027-1.3D
VPN & Public Wi-Fi Risk

VPN or Not to VPN

Location: Lakeview Hotel Business Center · Subject: Devon Park, marketing intern

Devon is working remotely for a week from a hotel. The hotel's Wi-Fi requires accepting a captive portal agreement but no password — anyone in the building can join. Devon has several tasks to get through before the end of the day and has to decide, task by task, how much risk each one carries and what to do about it.

For each task, select the risk level and the best action if using the hotel Wi-Fi without a VPN. Your selections are saved automatically.
Task on Hotel Wi-FiRisk LevelBest Action
Logging into an online banking app to pay a bill
Reading a public news website (no login)
Logging into a personal email account
Entering name and room number into the hotel's Wi-Fi captive portal
Connecting to the company's own VPN-protected intranet for a work file

Final Debrief

Synthesis · Topic 1.3 Essential Question