A network security technician is reviewing switch port traffic logs after receiving reports of unauthorized network sniffing on a corporate segment. The log packet trace reveals that a newly attached workstation sent dynamic negotiation frames configured with desirable trunking modes, successfully establishing a trunking link with the switch interface. Shortly after, frames with double-encapsulated 802.1Q headers were observed traversing the interface toward an isolated finance VLAN. Which of the following network attack types is indicated by these technical observations?
- VLAN HoppingCevap
- BMAC Flooding
- CARP Poisoning
- DDNS Poisoning
Cevap
VLAN Hopping is the network attack indicated by the technical observations.
The correct answer is VLAN Hopping. An attacker performs VLAN hopping either by spoofing DTP negotiation messages (causing an unmanaged port to become a trunk port) or by sending double-tagged 802.1Q frames. In double tagging, the outer tag matches the native VLAN of the switch port, causing the switch to strip the outer tag and forward the frame along the trunk carrying the inner tag intact to the target VLAN.
Adım Adım Çözüm
Anahtar Kavram
VLAN Hopping Attack Indicators
Tahmini Süre:1m 30s