A network administrator investigating wireless network instability observes that corporate laptops are repeatedly disconnected from the primary access point after receiving spoofed 802.11 management frames. Immediately following these disconnections, several client devices automatically connect to a nearby unauthorized access point broadcasting the same Service Set Identifier (SSID). Which of the following attack types is primary driver behind this network disruption?
- Wireless deauthentication attackCevap
- BAddress Resolution Protocol (ARP) poisoning
- CDomain Name System (DNS) cache poisoning
- DPort scanning and SYN flooding
Cevap
The correct attack vector is a wireless deauthentication attack.
The correct answer identifies a wireless deauthentication attack. In legacy 802.11 standards, management frames such as deauthentication requests are unencrypted and unauthenticated. Attackers exploit this vulnerability by spoofing the MAC address of the legitimate AP and transmitting deauth frames to force client disassociation, often driving clients onto an Evil Twin AP.
Adım Adım Çözüm
Anahtar Kavram
Wireless Deauthentication and Rogue AP (Evil Twin) Attack Vectors
Tahmini Süre:1m 15s