A security technician is investigating a multi-stage incident on an enterprise network segment. Packet logs reveal that an unauthorized internal host transmitted forged Gratuitous ARP messages to map the IP address of the default gateway to its own physical address. Simultaneously, internal users reported that entering legitimate domain names into their web browsers redirected them to a suspicious external IP address hosted on an unauthorized server. Which of the following attack types were executed during this incident? (Select TWO.)
- ARP PoisoningCevap
- DNS PoisoningCevap
- CMAC Flooding
- DVLAN Hopping
Cevap
The attack types executed in this scenario are ARP Poisoning and DNS Poisoning.
ARP Poisoning occurs when forged ARP messages alter the MAC-to-IP mapping on local hosts, misdirecting traffic intended for the gateway. DNS Poisoning alters domain name resolution data so that queries for legitimate web services return malicious IP addresses.
Adım Adım Çözüm
Anahtar Kavram
Identifying Man-in-the-Middle and redirection attack vectors based on network signatures