Soru

Zorluk: OrtaNetwork and Wireless Attack Indicators

An enterprise network administrator notices that several workstations on a local subnet are unexpectedly routing their outbound traffic through an unfamiliar host outside the designated gateway pool. Inspection of network packet captures reveals that workstations renewing their dynamic network configurations are accepting DHCPACK packets from a secondary, unauthorized server that responds faster than the corporate server. Which of the following attack indicators is demonstrated in this scenario?

  1. Rogue DHCP server deployment resulting in on-path traffic redirectionCevap
  2. B
    ARP cache poisoning flooding gratuitous ARP responses to override MAC addresses
  3. C
    DNS sinkholing intercepting and suppressing domain name resolution queries
  4. D
    MAC flooding overflowing switch memory tables to force unicast frame broadcasting

Cevap

Rogue DHCP server deployment resulting in on-path traffic redirection
The scenario indicates that workstations are receiving and accepting DHCPACK packets from an unauthorized secondary server that beats the legitimate server in response time. A rogue DHCP server operates by distributing unauthorized network configurations—such as a rogue default gateway or malicious DNS server address—allowing an attacker to intercept or redirect network traffic.

Adım Adım Çözüm

1
Analyze the observed network traffic indicators.
Workstations are receiving DHCPACK packets from an unauthorized secondary server providing a rogue default gateway address.
Identifying the protocol and packet type involved isolates the underlying attack mechanism.
2
Evaluate the impact of the packet responses on network traffic routing.
Workstations accept the faster unauthorized DHCPACK response, causing their traffic to route through an unintended gateway.
A rogue DHCP server operates by racing legitimate DHCP servers to assign forged network settings (such as rogue gateway or DNS IPs) to clients, enabling on-path positioning.

Anahtar Kavram

Rogue DHCP Server Attack Indicators
Tahmini Süre:1m 30s
Bu soruyu puanla