Soru

Zorluk: OrtaCommon Network Attack Types and Vectors

A network administrator investigating wireless network instability observes that corporate laptops are repeatedly disconnected from the primary access point after receiving spoofed 802.11 management frames. Immediately following these disconnections, several client devices automatically connect to a nearby unauthorized access point broadcasting the same Service Set Identifier (SSID). Which of the following attack types is primary driver behind this network disruption?

  1. Wireless deauthentication attackCevap
  2. B
    Address Resolution Protocol (ARP) poisoning
  3. C
    Domain Name System (DNS) cache poisoning
  4. D
    Port scanning and SYN flooding

Cevap

The correct attack vector is a wireless deauthentication attack.
The correct answer identifies a wireless deauthentication attack. In legacy 802.11 standards, management frames such as deauthentication requests are unencrypted and unauthenticated. Attackers exploit this vulnerability by spoofing the MAC address of the legitimate AP and transmitting deauth frames to force client disassociation, often driving clients onto an Evil Twin AP.

Adım Adım Çözüm

1
Analyze the observed anomaly and frame types in the incident description.
The attack explicitly utilizes spoofed 802.11 wireless management frames to disassociate connected clients from their legitimate access point.
Identifying the specific protocol layer and frame type isolates Layer 2 wireless disassociation mechanisms.
2
Correlate the client behavior following the disconnections.
Clients attempt to re-establish connectivity and connect to an unauthorized rogue AP broadcasting the same SSID (an Evil Twin setup).
Deauthentication attacks are typically executed to force endpoints to re-authenticate, driving them onto rogue access points controlled by an attacker.

Anahtar Kavram

Wireless Deauthentication and Rogue AP (Evil Twin) Attack Vectors
Tahmini Süre:1m 15s
Bu soruyu puanla