Soru

Zorluk: OrtaKey Security Concepts, Threats, Vulnerabilities, and Mitigations

A network security engineering team is analyzing threat vectors affecting enterprise switch and router infrastructure. Match each security threat scenario on the left with its primary technical mitigation mechanism on the right.

  • An attacker transmits forged ARP responses on a campus VLAN to intercept traffic intended for the default gateway.Dynamic ARP Inspection (DAI)
  • An attacker floods an edge router with high volumes of TCP SYN packets to exhaust CPU and control plane resources.Control Plane Policing (CoPP)
  • An unauthorized laptop connects to an unassigned Ethernet port in a conference room to gain access to internal subnet resources.802.1X Port-Based Network Access Control
  • An attacker performs automated dictionary login attempts against exposed SSH remote management endpoints.Multi-Factor Authentication (MFA) and Rate Limiting

Cevap

Forged ARP responses map to Dynamic ARP Inspection (DAI). Control plane TCP SYN flooding maps to Control Plane Policing (CoPP). Unauthorized wired switch port connection maps to 802.1X Port-Based Network Access Control. Automated SSH dictionary attacks map to Multi-Factor Authentication (MFA) and Rate Limiting.
Dynamic ARP Inspection checks ARP packets against trusted bindings to stop ARP poisoning. Control Plane Policing protects router processing resources by enforcing rate limits on traffic destined to the control plane. 802.1X enforces identity verification before opening switch port access. Multi-Factor Authentication combined with login rate limiting neutralizes automated password guessing.

Adım Adım Çözüm

1
Analyze Layer 2 address spoofing attacks on local switch subnets.
Identify ARP spoofing / poisoning as the threat vector.
Dynamic ARP Inspection intercepts and verifies invalid IP-to-MAC bindings using the DHCP snooping database.
2
Evaluate infrastructure plane threats targeting router CPU processing.
Identify control plane Denial-of-Service (DoS) exhaust attacks.
Control Plane Policing applies QoS policies directly to CPU-bound traffic queues to throttle malicious floods.
3
Examine physical access security and port-level network access control.
Identify unauthorized host connectivity on campus switch ports.
802.1X authenticates endpoints at Layer 2 before permitting traffic forwarding on the access switch port.
4
Assess administrative application threats targeting remote login services.
Identify credential harvesting and brute-force password attacks.
MFA ensures stolen or guessed passwords alone are insufficient, while rate limiting restricts high-frequency login attempts.

Anahtar Kavram

Classification of Network Security Threats and Primary Mitigation Controls
Tahmini Süre:2m 0s
Bu soruyu puanla