Soru

Zorluk: KolayNetwork and Wireless Attack Indicators

A network technician inspecting local subnet traffic notices a high volume of unsolicited Address Resolution Protocol (ARP) reply packets mapping the legitimate default gateway's IP address to an unknown host's MAC address. Which of the following network attacks is directly indicated by this activity?

  1. ARP poisoningCevap
  2. B
    DNS spoofing
  3. C
    MAC flooding
  4. D
    VLAN hopping

Cevap

ARP poisoning is indicated because unsolicited ARP responses alter the IP-to-MAC mapping cache on target hosts to intercept local network traffic.
The correct option is ARP poisoning because sending forged, unsolicited ARP responses to link the IP address of a default gateway to an unauthorized MAC address is the primary indicator of an ARP poisoning (or ARP spoofing) attack on a local Ethernet network.

Adım Adım Çözüm

1
Analyze the observed packet artifact in the scenario.
The technician observes unsolicited ARP replies mapping an IP address (default gateway) to an unexpected MAC address.
ARP (Address Resolution Protocol) operates at Data Link layer (Layer 2) to translate IPv4 addresses to hardware MAC addresses.
2
Correlate the packet artifact with known network attack signatures.
Sending fake, gratuitous, or unsolicited ARP responses to corrupt local ARP tables is the signature of ARP poisoning (spoofing).
By spoofing the MAC address of the default gateway, the attacker places themselves on-path to capture or manipulate traffic.

Anahtar Kavram

ARP Poisoning Attack Indicators
Bu soruyu puanla