Sniffing Defenses Flashcards
1
Q
Sniffing Defenses
A
- Encryptions
- Secure Protocols
- Physical Security
- Static instead of Dynamic Protocols
- Use IPv6
- Promiscuous Scanning Tools
2
Q
Switch Defenses
A
- Enable port security
- DHCP Snooping
- Port-based MAC
- Dynamic ARP inspection
- Disable Trunk Auto-Negotiation
- Avoid using default VLAN
- Force native VLAN tagging
- BDPU guard/root guard
3
Q
DNS Defenses
A
- DNS Sec
- Block outbound traffic to UDP 53
- Restrict external DNS queries (whitelist/blacklist)