Soru

Zorluk: OrtaNetwork and Wireless Attack Indicators

A network security technician is reviewing switch port traffic logs after receiving reports of unauthorized network sniffing on a corporate segment. The log packet trace reveals that a newly attached workstation sent dynamic negotiation frames configured with desirable trunking modes, successfully establishing a trunking link with the switch interface. Shortly after, frames with double-encapsulated 802.1Q headers were observed traversing the interface toward an isolated finance VLAN. Which of the following network attack types is indicated by these technical observations?

  1. VLAN HoppingCevap
  2. B
    MAC Flooding
  3. C
    ARP Poisoning
  4. D
    DNS Poisoning

Cevap

VLAN Hopping is the network attack indicated by the technical observations.
The correct answer is VLAN Hopping. An attacker performs VLAN hopping either by spoofing DTP negotiation messages (causing an unmanaged port to become a trunk port) or by sending double-tagged 802.1Q frames. In double tagging, the outer tag matches the native VLAN of the switch port, causing the switch to strip the outer tag and forward the frame along the trunk carrying the inner tag intact to the target VLAN.

Adım Adım Çözüm

1
Analyze the observed technical indicators in the packet trace.
Identified Dynamic Trunking Protocol (DTP) negotiation frames and double-encapsulated 802.1Q VLAN tags.
DTP allows switch interfaces to negotiate trunking links dynamically, while double 802.1Q encapsulation allows packets to jump from an outer access VLAN to an inner target VLAN when trunked.
2
Correlate the indicators with known Layer 2 attack mechanisms.
Dynamic trunk negotiation (switch spoofing) and double tagging are the two primary techniques used to perform VLAN hopping.
VLAN hopping allows an attacker on one VLAN to gain unauthorized access to traffic on another VLAN without traversing a router or firewall.

Anahtar Kavram

VLAN Hopping Attack Indicators
Tahmini Süre:1m 30s
Bu soruyu puanla