Soru

Zorluk: OrtaKey Security Concepts, Threats, Vulnerabilities, and Mitigations

A network security administrator is tasked with hardening campus access switch ports against Layer 2 security threats, specifically rogue DHCP server responses and ARP poisoning attacks. Which two mitigations should be implemented to prevent these threats? (Select two.)

  1. Dynamic ARP Inspection (DAI) to intercept and validate ARP requests and responses against a trusted binding databaseCevap
  2. B
    RADIUS payload encryption configured on access ports to encrypt all Layer 2 frame headers and traffic content
  3. DHCP Snooping to filter unauthorized DHCP server messages on untrusted ports and construct the binding databaseCevap
  4. D
    Port security configured with sticky MAC learning while omitting configuration persistence to the startup configuration

Cevap

Dynamic ARP Inspection (DAI) and DHCP Snooping are the correct mitigations for preventing ARP poisoning and rogue DHCP server attacks.
DHCP Snooping prevents rogue DHCP servers by blocking server responses on untrusted ports and builds a binding table. Dynamic ARP Inspection uses this binding table to validate ARP packets and block ARP spoofing attacks.

Adım Adım Çözüm

1
Identify the threat vectors presented in the scenario.
The scenario highlights two distinct Layer 2 attacks: rogue DHCP server deployments and ARP poisoning/spoofing attacks.
Accurate threat classification is essential for selecting appropriate switch-level defense controls.
2
Evaluate switch security features targeting rogue DHCP responses.
DHCP Snooping blocks unauthorized DHCP server packets on untrusted ports and creates the IP-MAC binding database.
DHCP Snooping directly addresses unauthorized address assignment and man-in-the-middle positioning via rogue DHCP servers.
3
Evaluate switch security features targeting ARP poisoning.
Dynamic ARP Inspection (DAI) inspects ARP packets and discards invalid IP-to-MAC mappings using the DHCP snooping table.
DAI relies on the binding database established by DHCP Snooping to prevent malicious host impersonation.

Anahtar Kavram

Layer 2 Threat Mitigations: DHCP Snooping and Dynamic ARP Inspection (DAI)
Bu soruyu puanla