Network Attacks and Security Threats: Types, Techniques, and Defenses

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/99

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 12:54 PM on 10/8/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

100 Terms

1
New cards

What is the primary tool used by modern attackers for various attacks?

The network

2
New cards

What are the three components of the CIA triad that network attacks may target?

Confidentiality, Integrity, Availability

3
New cards

What type of attack seeks to access sensitive data?

Confidentiality-violating attacks

4
New cards

What type of attack aims to alter information?

Integrity-targeting attacks

5
New cards

What is the goal of availability-targeting attacks?

To impair others' use of the network

6
New cards

How can network attacks be categorized?

By the part of the CIA triad they target, the layer of the network, or the specific protocols targeted.

7
New cards

What is adversary reconnaissance?

The process of gathering information about a target network, often starting with passive OSINT gathering.

8
New cards

What is a common tool used for active network scanning?

Port scanners

9
New cards

What does a TCP packet with all flags set, known as a Christmas tree packet, indicate?

It is used to gather information about a remote host's open ports.

10
New cards

What is fuzzing in the context of network attacks?

Inserting random or invalid data into header fields or application data inputs to learn how a service responds.

11
New cards

What is banner grabbing?

Sending a routine packet to a network service and analyzing the response for information about software and protocol versions.

12
New cards

Why are network scans considered active attacks?

They can reveal potential vulnerabilities and may be visible to network administrators.

13
New cards

What is address spoofing?

A technique where an attacker falsifies source information to facilitate an attack.

14
New cards

How can spoofing be used in network attacks?

By impersonating a known host or interface to bypass security controls.

15
New cards

What is MAC cloning?

A method that allows an attacker to bypass MAC address filtering by impersonating a permitted MAC address.

16
New cards

What is the drawback of spoofing a source IP address?

The attacker might not receive replies addressed to the forged IP.

17
New cards

What is the purpose of configuring firewalls and IDS/IPS in relation to network scans?

To limit the information an unauthorized scan reveals about the network.

18
New cards

What is the significance of the TCP 3-way handshake in network scanning?

It can be used to determine if a port is open and what services are running.

19
New cards

What type of attacks can target the physical hardware of a network?

Attacks that target the physical layer of the network.

20
New cards

What is the role of network protocols in security?

Some protocols are insecure by nature and can be vulnerable to attacks.

21
New cards

What is a common method to detect network scans?

Monitoring for unusual patterns of traffic that indicate scanning activity.

22
New cards

What is the relationship between network scans and more serious network attacks?

Network scans often precede more serious attacks, making their detection crucial.

23
New cards

What are some examples of social engineering tactics related to spoofing?

Spoofing email sender addresses or caller IDs in VoIP calls.

24
New cards

What is the potential impact of a successful fuzzing attack?

It can crash applications and hosts or gain access permissions.

25
New cards

What is the importance of understanding the vulnerabilities of network services?

Every network service has individual vulnerabilities that can be exploited.

26
New cards

What is the primary goal of many network attacks?

To exploit vulnerabilities in order to gain unauthorized access or disrupt services.

27
New cards

What does it mean for a protocol to be insecure by nature?

It has inherent weaknesses that make it vulnerable to attacks.

28
New cards

What is spoofing in network attacks?

Spoofing is a technique used to enable other attacks or make them more effective, often hiding the true source of an attack.

29
New cards

What is ARP poisoning?

ARP poisoning involves using spoofed ARP messages to alter the ARP cache of a target, allowing an attacker to eavesdrop or modify data.

<p>ARP poisoning involves using spoofed ARP messages to alter the ARP cache of a target, allowing an attacker to eavesdrop or modify data.</p>
30
New cards

What are the limitations of ARP poisoning?

ARP poisoning is limited to local network segments and has no inherent security measures.

31
New cards

What is DNS poisoning?

DNS poisoning redirects traffic by corrupting the DNS cache in a host or by compromising a DNS server.

32
New cards

How does DNS poisoning differ from ARP poisoning?

DNS poisoning can work beyond the Layer 2 segment, while ARP poisoning is limited to local networks.

33
New cards

What is pharming?

Pharming is a form of DNS poisoning that compromises DNS lookups or modifies the hosts file to redirect users to malicious sites.

34
New cards

What are rogue services in network attacks?

Rogue services imitate legitimate services, such as phishing sites or evil twin access points, to redirect traffic.

35
New cards

What is URL redirection?

URL redirection occurs when a website redirects users to a different URL, often used in phishing attacks.

36
New cards

What is domain hijacking?

Domain hijacking involves re-registering an expired domain or compromising the account controlling it to redirect traffic.

37
New cards

What is VLAN hopping?

VLAN hopping is when an attacker compromises VLAN control protocols to divert traffic to the wrong VLAN.

38
New cards

What are countermeasures against ARP poisoning?

Countermeasures include using switch security features to protect against ARP poisoning and VLAN hopping.

39
New cards

What is a denial-of-service (DoS) attack?

A DoS attack aims to deny network services to legitimate users, causing slowdowns or crashes.

40
New cards

What is the simplest method to achieve a DoS attack?

The simplest method is volumetric DoS, which floods the target with enough data or requests to exhaust resources.

41
New cards

What is a ping flood?

A ping flood is a type of DoS attack that sends excessive ICMP ping requests to consume a host's bandwidth.

42
New cards

What is a distributed denial-of-service (DDoS) attack?

A DDoS attack uses multiple attacking systems to generate overwhelming traffic, making it harder to block.

<p>A DDoS attack uses multiple attacking systems to generate overwhelming traffic, making it harder to block.</p>
43
New cards

What is a reflected DDoS attack?

A reflected DDoS attack uses IP spoofing to generate traffic from unrelated hosts, overwhelming the target.

44
New cards

What was the smurf attack?

The smurf attack involved pinging multiple systems with the target's IP address forged as the source, flooding the victim.

45
New cards

What are amplification techniques in DDoS attacks?

Amplification techniques produce more traffic or cause a fixed amount of traffic to consume more target resources.

46
New cards

What are common targets for reflected DDoS attacks?

Common targets include critical services like DNS or NTP, which can amplify the attack's impact.

47
New cards

What is the impact of DoS attacks on network performance?

DoS attacks can cause temporary slowdowns, crashes, or even hardware damage, disrupting regular functions.

48
New cards

What is the goal of a DoS attack?

The goal can be to inconvenience users, extort system owners, or destabilize a system for further exploits.

49
New cards

What is the difference between DoS and DDoS attacks?

DoS attacks come from a single source, while DDoS attacks involve multiple sources generating traffic.

50
New cards

What are the consequences of a successful DoS attack?

Consequences can include service denial, performance degradation, and potential hardware failure.

51
New cards

How can network administrators counteract DoS attacks?

Network administrators can block traffic from offending sites and configure servers to mitigate flood attacks.

52
New cards

What is the role of botnets in DDoS attacks?

Botnets are often used to conduct DDoS attacks, allowing attackers to leverage multiple compromised systems.

53
New cards

What is a DoS attack?

A Denial of Service attack aims to disrupt the normal functioning of a targeted server, service, or network by overwhelming it with traffic.

54
New cards

What is the purpose of sending oversized packets in a DoS attack?

Oversized packets can confuse a host and cause undesired behavior, potentially crashing the receiving application or allowing remote code execution.

55
New cards

What is a SYN flood attack?

A SYN flood attack abuses the TCP connection by sending a constant stream of SYN packets to open connections without responding to acknowledgments, leading to resource exhaustion.

56
New cards

How can malformed packets affect a system?

Malformed packets containing garbage data can cause a vulnerable application to crash or behave unpredictably, wasting application resources.

57
New cards

What is the impact of DoS attacks on operational technology (OT) devices?

DoS attacks on OT devices aim to disrupt physical operations, potentially causing permanent damage to machinery and facilities.

58
New cards

What was the purpose of the Stuxnet worm?

The Stuxnet worm was designed to infect centrifuges used in the Iranian nuclear program, altering their speeds to cause hardware failure.

59
New cards

What are some local means of conducting a DoS attack?

Local means include sabotaging power or network connections, corrupting software, or destroying hardware.

60
New cards

What is an example of a friendly DoS attack?

A friendly DoS attack occurs when a system is overwhelmed by unexpected levels of legitimate traffic due to a new product or news story.

61
New cards

What is packet sniffing?

Packet sniffing is the act of capturing and analyzing network traffic, often done by attackers to intercept sensitive information.

62
New cards

What is an on-path attack?

An on-path attack, also known as a man-in-the-middle (MITM) attack, occurs when an attacker intercepts and relays traffic between two hosts, impersonating each host to the other.

63
New cards

How can ARP cache poisoning be used in an on-path attack?

ARP cache poisoning involves sending spoofed ARP packets to convince a victim's NIC that the attacker's MAC address is that of a legitimate host, allowing interception of traffic.

64
New cards

What types of protocols are vulnerable to eavesdropping?

Protocols like HTTP, FTP, Telnet, POP, IMAP, SLIP, and SNMPv1 and v2 send sensitive data as unprotected plaintext, making them highly vulnerable to eavesdropping.

65
New cards

What is the role of a NIC in promiscuous mode?

A NIC in promiscuous mode can capture all packets on the network segment, even those not addressed to it, facilitating packet sniffing.

66
New cards

What is the goal of interception in network security?

The goal of interception is to capture sensitive information being transmitted over the network, such as login credentials, without the user's knowledge.

67
New cards

What is the significance of using encrypted protocols?

Encrypted protocols provide better security by protecting data from being easily intercepted and read by attackers.

68
New cards

What happens during a SYN flood attack?

During a SYN flood attack, a target server receives a large number of SYN packets, leading to a backlog of half-open connections that prevent legitimate users from connecting.

69
New cards

What is the purpose of the hping3 utility in a DoS attack exercise?

The hping3 utility is used for crafting and sending arbitrary network packets, including those used in DoS flood attacks.

70
New cards

What is the expected outcome of launching a SYN flood attack?

The expected outcome is a spike in network traffic and alerts in the intrusion detection system (IDS) due to the high volume of SYN packets.

71
New cards

What can be a consequence of a successful DoS attack on OT devices?

A successful DoS attack on OT devices can disrupt critical physical operations and potentially cause significant damage.

72
New cards

What is the role of Task Manager in monitoring a DoS attack?

Task Manager can be used to view network traffic levels and monitor the impact of a DoS attack on system performance.

<p>Task Manager can be used to view network traffic levels and monitor the impact of a DoS attack on system performance.</p>
73
New cards

What is the effect of signal jamming on wireless networks?

Signal jamming disrupts wireless communications, effectively serving as a DoS attack by preventing legitimate users from accessing the network.

74
New cards

What is the significance of monitoring tools like barnyard2.exe during a DoS attack?

Monitoring tools like barnyard2.exe help analyze and report on network traffic and alerts generated by intrusion detection systems during a DoS attack.

75
New cards

What are some common methods for intercepting network traffic?

Common methods include physically tapping into cables, using wireless sniffers, and exploiting network vulnerabilities to gain access.

76
New cards

How does network segmentation help against packet sniffing?

Network segmentation makes it more difficult for attackers to capture traffic by isolating different segments of the network.

77
New cards

How does Mallory facilitate an on-path attack?

Mallory relays messages between Alice and Bob, making it appear as if they are communicating directly.

78
New cards

What is a replay attack?

An attack where the attacker intercepts data transmissions and resends them to disrupt communications or gain unauthorized access.

79
New cards

How can replay attacks be mitigated?

By using timestamps and number sequences that are not updated in replayed communications.

80
New cards

What is session replay/hijacking?

An application-level replay attack targeting session-based protocols, allowing an attacker to take over an existing session.

81
New cards

What distinguishes session hijacking from session replay?

Session hijacking occurs immediately after the client logs in, while session replay can happen later.

82
New cards

What is a downgrade attack?

An attack that tricks clients into using weaker encryption methods by interfering with the initial connection setup.

83
New cards

What is SSL stripping?

An on-path attack that bypasses secure connections by relaying messages between a client and server using plaintext.

84
New cards

What is a browser-based on-path attack?

An attack where malware modifies the user's web experience, potentially bypassing strong network encryption.

85
New cards

What is the main advantage of on-path attacks over passive eavesdropping?

On-path attacks can intercept and modify encrypted conversations by negotiating separate encryption with each host.

86
New cards

What can an attacker do during an on-path attack on a banking transaction?

The attacker can change transaction amounts and destinations, and send false confirmation information back to the user.

87
New cards

What is the purpose of using a packet sniffer like Wireshark?

To capture and analyze network traffic, which can include sensitive information like passwords.

<p>To capture and analyze network traffic, which can include sensitive information like passwords.</p>
88
New cards

What is FTP and why is it insecure?

FTP is a plaintext protocol that transmits data, including usernames and passwords, without encryption.

<p>FTP is a plaintext protocol that transmits data, including usernames and passwords, without encryption.</p>
89
New cards

How can an attacker replicate the method of capturing credentials?

By gaining access to the communication path, such as through a SPAN port or traffic redirection.

90
New cards

What are some ways to reduce the risk of credential theft?

Using secure protocols like FTPS or SFTP, blocking insecure protocols with ACLs, and implementing network segmentation.

91
New cards

What is the CIA triad in cybersecurity?

Confidentiality, Integrity, and Availability; a framework for understanding security goals.

92
New cards

Why is gaining access to a sensitive system valuable for an attacker?

It allows the attacker to compromise the CIA triad and pivot to attack the entire network.

93
New cards

What is a common method for attackers to bypass access controls?

Targeting systems that lack authentication or have users logged in without a password.

94
New cards

What is the significance of stealing passwords in cyber attacks?

Stealing passwords is a common goal for hackers and social engineers to gain unauthorized access.

95
New cards

What can be done to protect against unauthorized access on a network?

Implementing strong authentication measures and securing network services that do not require authentication.

96
New cards

What is one common goal of hackers and social engineers?

Stealing passwords.

97
New cards

What is credential harvesting?

The process of stealing credentials, including passwords and private keys.

98
New cards

How can physical intruders obtain passwords?

By looking for sticky notes or monitoring unencrypted network traffic.

99
New cards

What is a card cloner?

A device that reads ID cards and produces a working facsimile.

100
New cards

What do skimmers do?

They capture card information and PINs from ATMs.