nerdexam
CompTIA

PT0-002 · Question #125

Click the exhibit button. A penetration tester is performing an assessment when the network administrator shows the tester a packet sample that is causing trouble on the network. Which of the…

The correct answer is B. ARP spoofing. The penetration tester should stop ARP spoofing, as it involves manipulating ARP tables to misdirect network traffic, a common cause of network disruptions and 'trouble on the network'.

Attacks and Exploits

Question

Click the exhibit button. A penetration tester is performing an assessment when the network administrator shows the tester a packet sample that is causing trouble on the network. Which of the following types of attacks should the tester stop?

Exhibit

PT0-002 question #125 exhibit

Options

  • ASNMP brute forcing
  • BARP spoofing
  • CDNS cache poisoning
  • DSMTP relay

How the community answered

(22 responses)
  • A
    18% (4)
  • B
    73% (16)
  • C
    5% (1)
  • D
    5% (1)

Why each option

The penetration tester should stop ARP spoofing, as it involves manipulating ARP tables to misdirect network traffic, a common cause of network disruptions and 'trouble on the network'.

ASNMP brute forcing

SNMP brute forcing is an attempt to guess credentials for network device management and typically does not cause direct network traffic disruption or 'trouble' in the same manner.

BARP spoofingCorrect

ARP spoofing is a network-layer attack where an attacker sends forged ARP (Address Resolution Protocol) messages over a local area network, associating the attacker's MAC address with the IP address of a legitimate device. This redirects traffic, causing network disruptions and enabling Man-in-the-Middle attacks, directly leading to 'trouble on the network.'

CDNS cache poisoning

DNS cache poisoning manipulates DNS resolution to redirect traffic to malicious sites, but its immediate impact on general network operation is less direct than ARP spoofing's traffic misdirection.

DSMTP relay

SMTP relay involves using an SMTP server to send emails, often unsolicited, which is a service abuse but not a network-layer attack causing broad network 'trouble'.

Concept tested: Network attacks - ARP spoofing

Source: https://attack.mitre.org/techniques/T1557/002/

Topics

#ARP spoofing#Network attacks#Man-in-the-Middle#Packet analysis

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice