EHE: Chapter 6-Network Level Attack and Countermeasures

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/42

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:53 PM on 10/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

43 Terms

1
New cards

Which of the following protocols distributes, inquiries into, retrieves, and posts news articles using a reliable stream-based transmission of news among the ARPA-Internet community?

NNTP

2
New cards

Which of the following protocols is vulnerable to a sniffing attack as passwords and data are sent in clear text?

FTP

3
New cards

Which of the following protocols is a TCP/IP-based protocol used to exchange management information between devices connected on a network?

snmp

4
New cards

telnet

is a protocol used for communicating with a remote host (via port 23) on a network using a command-line terminal

5
New cards

POP

allows a user’s workstation to access mail from a mailbox server. A user can send mail from the workstation to the mailbox server via SMTP.

6
New cards

SNMP

TCP/IP-based protocol used for exchanging management information between devices connected on a network. The first version of SNMP (SNMPv1) does not offer strong security, which leads to the transfer of data in a cleartext format.

7
New cards

In which of the following OSI layers do sniffers operate and perform an initial compromise?

data link

8
New cards

Smith, a professional hacker, initiated a network sniffing attack on the switched Ethernet environment of a target organization. He employed an automated tool to flood the switch with a fake physical address until the switch translation table became full. When the switch entered fail-open mode, it started acting as a hub by broadcasting packets. Now, Smith could easily accomplish his goal of network sniffing.

Identify the type of attack performed by Smith in the above scenario.

MAC flooding

9
New cards

Clark, a professional hacker, targeted an organization’s network to steal credentials being shared during active sessions. He collected the physical address of the legitimate users connected to the switch port. Then, Clark started spoofing his physical address with the physical address of a legitimate client and received all the traffic destined for that client.

Which of the following attacks has Clark performed in the above scenario?

MAC duplicating

10
New cards

DNS poisoning

the attacker tricks a DNS server into believing that it has received authentic information when, in reality, it has not received any. The attacker tries to redirect the victim to a malicious server instead of the legitimate server.

11
New cards

ARP spoofing

involves constructing a large number of forged ARP request and reply packets to overload a switch. When a machine sends an ARP request, it assumes that the ARP reply will come from the right machine

12
New cards

DHCP Starvation

an attacker floods the DHCP server by sending numerous DHCP requests and uses all of the available IP addresses that the DHCP server can issue.

13
New cards

MAC duplicating attack

the attacker first retrieves the MAC addresses of clients who are actively associated with the switch port. Then, the attacker spoofs a MAC address with the MAC address of the legitimate client. If the spoofing is successful, then the attacker can receive all the traffic destined for the client.

14
New cards

George, a professional hacker, targeted an organization’s server to cause reputational damage to the organization. For this purpose, he employed an ARP poisoning tool that forges ARP replies from the target server resulting in customers navigating to the attacker-owned host, which contains irrelevant information for the customers.

Which of the following tool helped George in the above scenario to perform an ARP poisoning attack?

Ettercap

15
New cards

Trape

is an OSINT analysis and research tool, which allows people to track and execute intelligent social engineering attacks in real time.

16
New cards

LUCY

enables organizations to take on the role of an attacker (phishing simulation) and identify gaps in both the technical infrastructure and security awareness.

17
New cards

Netstat

tool helps in collecting information about network connections operative in a Windows system.

18
New cards

Which of the following tool helps an attacker perform an ARP poisoning attack?

BetterCAP

19
New cards

Identify the technique that sends non-broadcast ARP to all the nodes in the network, and the node that runs in promiscuous mode broadcasts a ping message on the network with the local IP address but a different MAC address.

ARP method

20
New cards

Which of the following techniques is useful in detecting a system that runs in promiscuous mode and in turn helps detect sniffers installed on the network?

Ping method

21
New cards

Williams, a professional hacker, was hired by an organization to damage the reputation of their rival company. Williams spoofed a customer’s rival company’s IP address and initiated sending multiple ICMP ECHO request packets to an IP broadcast network. As a result, all the hosts together started sending responses to the customer’s IP address. These responses were sent to the customer machine, diverting significant traffic toward it and crashing it in the process.

Identify the type of attack performed by Williams in the above scenario.

Smurf Attack

22
New cards

Smurf Attack

, the attacker spoofs the source IP address with the victim’s IP address and sends a large number of ICMP ECHO request packets to an IP broadcast network.

23
New cards

Ping of death

attacker attempts to crash, destabilize, or freeze the target system or service by sending malformed or oversized packets using a simple ping command.

24
New cards

Fragmentation attack

destroys a victim’s ability to reassemble fragmented packets by flooding it with TCP or UDP fragments, resulting in reduced performance.

25
New cards

SYN flood attack

in a SYN attack, the attacker sends a large number of SYN requests to the target server (victim) with fake source IP addresses. The attack creates incomplete TCP connections that use up network resources.

26
New cards

Identify the attack technique that purely targets hardware devices by exploiting their security flaws and causes irreversible damage to the system hardware, requiring the victim to replace the hardware. 

Phlashing

27
New cards

Phlashing

, purely target hardware and cause irreversible damage to the hardware. Unlike other types of DoS attacks, it sabotages the system hardware, requiring the victim to replace or reinstall the hardware.

28
New cards

ARP spoofing

involves constructing a large number of forged ARP request and reply packets to overload a switch.

29
New cards

DHCP Starvation attack

In a DHCP starvation attack, an attacker floods the DHCP server by sending numerous DHCP requests and uses all of the available IP addresses that the DHCP server can issue. As a result, the server cannot issue any more IP addresses, leading to a DoS attack.

30
New cards

MAC flooding

is a technique used to compromise the security of network switches that connect network segments or devices. Attackers use the MAC flooding technique to force a switch to act as a hub so that they can easily sniff the traffic.

31
New cards

Rachel, a network pen tester, was inspecting her organization’s network and web applications and was testing whether they were vulnerable to service disruption. She utilized a tool that could perform network stress testing and perform a DoS attack by flooding the server with TCP packets to interrupt the normal services.

Which of the following tool was utilized by Rachel in the above scenario?

Low orbit ion cannon

32
New cards

Noah, a professional hacker, planned to launch a DDoS attack on his target organization and disrupt their normal services. He employed a tool designed to attack up to 256 target URLs simultaneously, and it can also send HTTP POST and GET requests to a computer that uses lulz-inspired GUIs.

Which of the following tool helped Noah perform the DDoS attack?

High orbit ion cannon

33
New cards

Joe, an attacker, was hired to target a company’s server and make its services unavailable to valid users. Joe employed a command-line-oriented tool to initiate a DoS attack on the targeted website’s server by crafting custom ICMP echo request packets.

Which of the following command-line tool helped Joe launch the DoS attack?

hping3

34
New cards

Lopez, a professional hacker, targets his opponent’s system and performs spoofing attacks by using multiple intermediary and secondary machines. He exploited the TCP three-way handshake vulnerability and initiated sending requests to the intermediary hosts, reflecting the attack traffic to the target.

Identify the attack technique employed by Lopez in the above scenario.

DRDOS attack

35
New cards

DRDOS attack

k, involves the use of multiple intermediary and secondary machines that contribute to a DDoS attack against a target machine or application. A DRDoS attack exploits the TCP three-way handshake vulnerability.

36
New cards

Peer to peer attack

is a form of DDoS attack in which the attacker exploits a number of bugs in peer-to-peer servers to initiate a DDoS attack. Attackers exploit flaws found in networks that use the Direct Connect (DC++) protocol, which allows the exchange of files between instant-messaging clients.

37
New cards

Which of the following countermeasures helps security teams defend against DoS and DDoS attacks on the network and system?

prevent the use of get

38
New cards

Which of the following best practices should be followed to thwart DoS/DDoS attacks?

Block all inbound packet orginating from service port

39
New cards

Jack, a professional hacker, has targeted a website that uses linear algorithms to create shorter session IDs for logged-in users. Jack created a forged valid session ID and logged in to other accounts by studying the sequential pattern.

Which of the following weaknesses has Jack exploited in the above scenario to hijack session IDs?

Weak session ID generation

40
New cards

James, a professional hacker, performed a session hijacking attack against a victim connected to the same network. James captured the TCP sequence and acknowledgment numbers of the victim to craft his own packets. He then interrupted the connection between the server and the victim and injected the crafted packets into the server as a legitimate user.

Given below are different steps followed by James when performing session hijacking:

  1. Session desynchronization

  2. Monitor

  3. Session ID prediction

  4. Sniff

  5. Command injection

Identify the correct sequence of steps involved in session hijacking.

4 -> 2 -> 1 -> 3 -> 5

41
New cards

In which of the following techniques does an attacker predict the sequence numbers that a victim host sends to create a connection that appears to originate from the host and then hijacks the communication?

blind hijacking

42
New cards

In which of the following session hijacking phases does an attacker break the connection to the victim’s machine by knowing the next sequence number (NSN)?

Sequence desynchronization

43
New cards

David, a network administrator, was assigned to analyze the network for signatures of a session hijacking attack on an organization. David captured all the network traffic using packet sniffing tools and used various filters to find any repeated ARP update packets.

Which of the following methods has David employed in the above scenario to detect session hijacking attacks?

manual method