Soru

Zorluk: OrtaCommon Network Attack Types and Vectors

During a network security audit, a security analyst identifies an ongoing Man-in-the-Middle (MitM) attack occurring within a local Ethernet switch segment. Packet captures reveal that workstation ARP tables are incorrectly binding the default gateway's IP address to an unauthorized endpoint's MAC address. Which of the following technical mechanisms or indicators are directly associated with this attack vector? (Select TWO.)

  1. Transmission of forged gratuitous ARP frames to corrupt IP-to-MAC binding tables on local endpointsCevap
  2. Interception and potential modification of unencrypted Layer 2 frames routed through the attacker's hardware addressCevap
  3. C
    Exploitation of open recursive resolvers to direct high-volume reflected UDP response traffic against a target host
  4. D
    Alteration of authoritative AAAA resource records on an external name server to compromise hostname resolution

Cevap

The technical mechanisms associated with this ARP poisoning attack are the transmission of forged gratuitous ARP frames to alter local IP-to-MAC cache tables and the interception or modification of unencrypted Layer 2 frames passing through the spoofed hardware address.
The scenario describes ARP cache poisoning, a local Layer 2 attack where an adversary broadcasts forged gratuitous ARP replies. This overwrites host ARP tables to associate the gateway IP with the attacker's MAC address, allowing the attacker to intercept and modify unencrypted traffic.

Adım Adım Çözüm

1
Analyze the incident symptoms presented in the scenario.
The incorrect binding of the default gateway IP address to an unauthorized host MAC address indicates an ARP cache poisoning attack on the local switch segment.
ARP cache poisoning specifically targets Layer 2 address resolution tables so local network traffic is misrouted to an attacker's network interface.
2
Identify the technical mechanisms used to execute local ARP poisoning.
The attacker broadcasts unsolicited gratuitous ARP packets with forged IP-to-MAC pairings, causing host systems to update their ARP tables and forward unencrypted frames through the attacker's hardware address.
The ARP protocol lacks built-in authentication, causing endpoints to implicitly trust received ARP updates.
3
Differentiate ARP cache poisoning from external attacks such as DNS record tampering and DDoS amplification.
DNS record manipulation and UDP reflector amplification target external name resolution infrastructure and bandwidth availability, whereas ARP poisoning operates exclusively within the local broadcast domain at Layer 2.
Evaluating protocol layers differentiates local data-link attacks from transport or application layer service disruptions.

Anahtar Kavram

ARP Poisoning and Man-in-the-Middle (MitM) Attacks
Bu soruyu puanla