A network security administrator monitoring enterprise switch logs notices that a single Media Access Control (MAC) address is rapidly alternating between two different physical switch ports. This constant port-flapping anomaly is causing frame misdirection across the local subnet. Which of the following attack types is most likely occurring?
- MAC spoofingCevap
- BARP poisoning
- CDNS cache poisoning
- DRadio frequency jamming
Cevap
The attack indicated by the rapid alternation of a single MAC address across multiple switch ports is MAC spoofing.
MAC spoofing occurs when an attacker modifies their network interface MAC address to mirror an authorized device. Transmitting traffic from two devices using identical MAC addresses forces the network switch to continuously rebind the MAC address to different ports, generating port-flapping indicators in syslog.
Adım Adım Çözüm
Anahtar Kavram
MAC Spoofing Indicators
Tahmini Süre:45s