A network administrator receives an alert from an Intrusion Detection System (IDS) displaying the following log entries captured from a local subnet:
[WARN] Unsolicited ARP Reply detected: 192.168.1.1 is at 00:11:22:AA:BB:CC (Previous MAC: 00:00:0C:07:AC:01)
[WARN] Unsolicited ARP Reply detected: 192.168.1.1 is at 00:11:22:AA:BB:CC (Host 192.168.1.45 ARP cache updated)
[INFO] Traffic for default gateway 192.168.1.1 rerouted through 00:11:22:AA:BB:CC
Based on these technical indicators, which of the following network attacks is actively occurring?
- ARP poisoningCevap
- BMAC flooding
- CDNS spoofing
- DRogue DHCP server deployment
Cevap
ARP poisoning is the network attack being performed.
The correct option correctly identifies ARP poisoning. Gratuitous or unsolicited ARP replies that map a legitimate gateway IP address to a foreign MAC address are the definitive indicator of ARP cache poisoning, allowing an attacker to intercept or modify local network traffic.
Adım Adım Çözüm
Anahtar Kavram
ARP Cache Poisoning / ARP Spoofing