Soru

Zorluk: OrtaCommon Network Attack Types and Vectors

An enterprise network security administrator discovers anomalous traffic on a switch interface where an attacker on VLAN 10 sent frames directly to a target server on VLAN 20 without passing through a router. Analysis of captured frames reveals two 802.1Q tags embedded within the Ethernet header. Which of the following conditions must be met for this double-tagging VLAN hopping attack to succeed? (Select TWO.)

  1. The native VLAN of the 802.1Q trunk link must match the attacker's access VLAN.Cevap
  2. The traffic must traverse an 802.1Q trunk line connecting two switches.Cevap
  3. C
    The attacker must spoof the target server's MAC address in the local ARP table prior to frame transmission.
  4. D
    The target host must resolve network services using an application-layer CNAME record.

Cevap

Double-tagging VLAN hopping requires that the native VLAN of the trunk link matches the attacker's VLAN, and that the traffic traverses an 802.1Q trunk connecting switches.
A double-tagging attack succeeds when the attacker's access VLAN matches the native VLAN configured on an 802.1Q trunk port. Upon receiving the frame, the first switch strips the outer tag because it matches the native VLAN. The frame travels across the trunk to the second switch, which reads the inner 802.1Q tag and forwards the frame to the target VLAN, bypassing router access controls.

Adım Adım Çözüm

1
Analyze the incident details
The capture shows dual 802.1Q headers used to hop from VLAN 10 to VLAN 20 across a switch infrastructure.
Identifying double tagging isolates the specific conditions required for native VLAN header stripping on switch trunks.
2
Evaluate native VLAN processing behavior
When a frame's outer 802.1Q tag matches the trunk's native VLAN, the first switch strips the outer tag before sending the frame across the trunk.
This establishes that the attacker's VLAN must match the native VLAN of the trunk port.
3
Evaluate downstream switch trunk processing
The second switch inspects the remaining inner 802.1Q tag and forwards the frame to the destination VLAN specified in that tag.
This demonstrates that an active switch-to-switch trunk link is necessary for the second switch to interpret the inner tag.

Anahtar Kavram

Double-tagging VLAN hopping exploits native VLAN stripping mechanisms over 802.1Q trunk links to send unidirectional frames to a different VLAN without passing through a Layer 3 device.
Bu soruyu puanla