MODULE 8: Sniffing Flashcards

1
Q

What describes a sniffing technique in which altered DNS records are used to redirect online traffic to a fraudulent website that resembles its intended destination?

ARP Poisoning
Mac Flooding
DHCP Attacks
DNS Poisoning

A

DNS Poisoning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What describes is a type of sniffing attack carried out over a Local Area Network (LAN) that involves sending malicious ARP packets to a default gateway on a LAN in order to change the pairings in its IP to MAC address table?

MAC Flooding
DHCP Attack
ARP Poisoning
DNS Poisoning

A

ARP Poisoning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

At what layer of the OSI model do sniffers operate?

data link layer
network layer
physical layer
application layer

A

data link layer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What term describes copying data from multiple ports to a single port to allow inspection of all traffic through a switch port analyzer (SPAN)?

Port Switching
Port Forwarding
Port Mirroring

A

Port Mirroring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What type of attack is described by flooding the CAM table with fake MAC addresses and IP pairs until it is full?

The switch then acts as a hub and broadcasts traffic to the whole network allowing for easy sniffing.

MAC Flooding
Switch port Stealing
Easy Switching

A

MAC flooding

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What protocol uses port UDP 67 (server) and UDP 68 (client)?

LDAP
DHCP
DNS
FTP

A

DHCP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which protocol is used to dynamically lease IP addresses to hosts?

NTP
DHCP
SMTP
SSH

A

DHCP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

SLIDE 23

A

SLIDE 23

How well did you know this?
1
Not at all
2
3
4
5
Perfectly