Soru

Zorluk: KolayKey Security Concepts, Threats, Vulnerabilities, and Mitigations

An attacker on a local Ethernet network sends spoofed ARP messages to associate their MAC address with the IP address of the default gateway, allowing them to secretly intercept and relay network traffic between a victim host and the router. Which type of security threat is being executed?

  1. Man-in-the-middle (MitM) attackCevap
  2. B
    Distributed Denial of Service (DDoS) attack
  3. C
    Social engineering attack
  4. D
    Trojan horse malware infection

Cevap

Man-in-the-middle (MitM) attack
A Man-in-the-middle (MitM) attack occurs when an unauthorized entity places itself between two communicating network endpoints. ARP spoofing on a local Ethernet segment is a primary technique used to execute a MitM attack at Layer 2.

Adım Adım Çözüm

1
Analyze the attack mechanism described in the scenario.
The attacker sends spoofed ARP responses mapping their MAC address to the default gateway's IP address.
This causes local endpoints to update their ARP tables and send frames intended for the router to the attacker's device instead.
2
Classify the security threat based on the attacker's operational position and capability.
The attacker can read, alter, or drop packets passing between the victim host and the default gateway without either party realizing.
Interception and relaying of communication between two unaware parties is defined as a Man-in-the-middle (MitM) attack.

Anahtar Kavram

Man-in-the-Middle (MitM) Threats and ARP Spoofing
Tahmini Süre:45s
Bu soruyu puanla