An enterprise network administrator notices that several workstations on a local subnet are unexpectedly routing their outbound traffic through an unfamiliar host outside the designated gateway pool. Inspection of network packet captures reveals that workstations renewing their dynamic network configurations are accepting DHCPACK packets from a secondary, unauthorized server that responds faster than the corporate server. Which of the following attack indicators is demonstrated in this scenario?
- Rogue DHCP server deployment resulting in on-path traffic redirectionCevap
- BARP cache poisoning flooding gratuitous ARP responses to override MAC addresses
- CDNS sinkholing intercepting and suppressing domain name resolution queries
- DMAC flooding overflowing switch memory tables to force unicast frame broadcasting
Cevap
Rogue DHCP server deployment resulting in on-path traffic redirection
The scenario indicates that workstations are receiving and accepting DHCPACK packets from an unauthorized secondary server that beats the legitimate server in response time. A rogue DHCP server operates by distributing unauthorized network configurations—such as a rogue default gateway or malicious DNS server address—allowing an attacker to intercept or redirect network traffic.
Adım Adım Çözüm
Anahtar Kavram
Rogue DHCP Server Attack Indicators
Tahmini Süre:1m 30s