nerdexam
Cisco

210-260 · Question #80

If you change the native VLAN on the port to an unused VLAN, what happens if an attacker attempts a double tagging attack?

The correct answer is C. A VLAN hopping attack would be prevented. The key feature of a double tagging attack is exploiting the native VLAN. Since VLAN 1 is the default VLAN for access ports and the default native VLAN on trunks, it’s an easy target. The first countermeasure is to remove access ports from the default VLAN 1 since the…

Secure Routing and Switching

Question

If you change the native VLAN on the port to an unused VLAN, what happens if an attacker attempts a double tagging attack?

Options

  • AThe trunk port would go into an error-disable state.
  • BA VLAN hopping attack would be successful
  • CA VLAN hopping attack would be prevented
  • Dthe attacked VLAN will be pruned

How the community answered

(46 responses)
  • A
    7% (3)
  • B
    2% (1)
  • C
    80% (37)
  • D
    11% (5)

Explanation

The key feature of a double tagging attack is exploiting the native VLAN. Since VLAN 1 is the default VLAN for access ports and the default native VLAN on trunks, it’s an easy target. The first countermeasure is to remove access ports from the default VLAN 1 since the attacker’s port must match that of the switch’s native VLAN.

Topics

#double tagging attack#native VLAN#VLAN hopping#802.1Q defense

Community Discussion

No community discussion yet for this question.

Full 210-260 Practice