Question

Difficulty: EasyNetwork and Wireless Attack Indicators

Match each network or wireless security threat on the left with its corresponding technical indicator or observed evidence on the right.

  • BluesnarfingUnauthorized exfiltration of contact lists and messages from a mobile device via an active Bluetooth connection.
  • Wireless Disassociation AttackTransmission of spoofed 802.11 management frames that force connected clients to drop their Wi-Fi connection.
  • DNS PoisoningCorrupted domain name resolution cache entries redirecting legitimate user web traffic to malicious IP addresses.
  • Rogue Access PointAn unauthorized physical wireless router connected directly to an unmonitored Ethernet port inside the corporate firewall.

Answer

Bluesnarfing matches unauthorized exfiltration of contact lists and messages via Bluetooth. Wireless Disassociation Attack matches transmission of spoofed 802.11 management frames forcing clients offline. DNS Poisoning matches corrupted domain name resolution cache entries redirecting web traffic. Rogue Access Point matches an unauthorized physical wireless router connected directly to an internal network port.
Each attack type matches its distinct indicator: Bluesnarfing steals data via Bluetooth; Wireless Disassociation sends spoofed 802.11 management frames to disconnect clients; DNS Poisoning tampers with DNS cache records to misdirect web requests; and a Rogue Access Point is an unapproved physical wireless device connected to an internal network switch port.

Step-by-Step Solution

1
Identify the primary mechanism of Bluesnarfing.
Recognize that Bluesnarfing exploits Bluetooth vulnerabilities to steal private data such as contacts or calendar items.
Bluesnarfing is defined by unauthorized data theft over Bluetooth.
2
Analyze the Wireless Disassociation Attack mechanisms.
Connect this attack to 802.11 wireless management frames that command clients to disassociate from their access point.
Attackers send spoofed deauthentication frames to disrupt connectivity.
3
Examine DNS Poisoning indicators.
Link DNS poisoning to corrupted resolution records residing in DNS caches redirecting domain names to malicious destinations.
DNS poisoning tampers with domain-to-IP mappings.
4
Identify the characteristic of a Rogue Access Point.
Match it with an unauthorized physical wireless access point connected to an internal network port.
Rogue APs bypass perimeter controls by plugging directly into internal switch ports.

Key Concept

Network and Wireless Attack Indicators
Rate this question