ETExamTower
Q41Security Fundamentals

Drag and drop the attack-mitigation techniques on the left to the attack types they mitigate on the right. <DragDrop items={["Configure the 802.1x authentication protocol","Configure the DHCP snooping feature","Configure the native VLAN with a nondefault VLAN","Disable Dynamic Trunking Protocol – switch-spoofing VLAN-hopping attack"]} slots={[{"answer":"Configure the native VLAN with a nondefault VLAN","id":"slot1","label":"802.1q double-tagging VLAN-hopping attack"},{"answer":"Configure the 802.1x authentication protocol","id":"slot2","label":"MAC flooding attack"},{"answer":"Configure the DHCP snooping feature","id":"slot3","label":"man-in-the-middle spoofing attack"},{"answer":"Disable Dynamic Trunking Protocol – switch-spoofing VLAN-hopping attack","id":"slot4","label":"switch-spoofing VLAN-hopping attack"}]} explanation={"Double-tagging VLAN hopping exploits the native VLAN on an 802.1Q trunk, so moving the native VLAN away from the default VLAN mitigates that attack. Switch-spoofing VLAN hopping depends on trunk negotiation, so disabling DTP prevents an attacker from forming an unauthorized trunk. DHCP snooping helps prevent spoofing-based man-in-the-middle behavior by building trusted IP-to-MAC bindings and blocking rogue DHCP activity that supports impersonation attacks. 802.1X requires endpoint authentication before a port is usable, reducing the ability of unauthorized devices to connect and perform attacks such as MAC flooding.\n\n**Learn more:** [VLAN Configuration Guide - Configure VLAN Trunking](https://www.cisco.com/c/en/us/td/docs/switches/lan/c9000/lyr2-fwd/vlan/vlan-configuration-guide/configure-vlan-trunks.html) · [Security Configuration, Cisco Catalyst PON Series Switches - Preventing ARP Spoofing and Flood Attack](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst_pon/software/configuration_guide/sec/b-gpon-config-security/preventing_arf_spoofing_and_flood_attack.html)"} reuse={false} />

← → navigate · a answer
Discussion · 10
45
MAC flooding attack ----> Configure 802.1x MITM spoofing attack (read: rogue DHCP server) -----> Configure DHCP snooping
14
I think the answers are corect.
11
Thank goodness for all the community in this paid for area. So close to the end just a few hundred to go. I reckon overall its worth it just to have had sight of close to 'real' exam questions. The fact that for large parts we have to 'research' helps in itself. Though where even with community input we cant agree an answer, thats generally because the question is nonsense..... Thanks :)
9
oatmeal turkey is correct: MITM Attacks - DHCP Snooping MAC Flooding - 802.1X Authentication 802.1Q Double Tagged VLAN Hopping Attacks - Change Native VLAN To non-default VLAN Switch Spoofing VLAN Hopping - Disable DTP (Set Switchport to Nonnegotiate)
2
i mean incorrect lol
2
This question is not sane. The model answers are correct, except for the technique to mitigate against MAC flooding attack. Whilst 802.1x is all that's left, this will not work. The correct answer would be to use port security and limit the number of MACs allowed.
2
Given answers are correct. Even the next question 971 ask the option that is vulnerable to MIDM attack and answer is telnet and what do you use to avoid the vulnerability? ssh which is authentication.
1
i agree, the answers are correct
1
Provided answer is correct. https://www.securew2.com/blog/preventing-man-in-the-middle-mitm-attacks-the-ultimate-guide
1
Given answers are correct : MITM Attacks: 802.1X enforces mutual authentication to eliminate the potential of man-in-the-middle (MITM) attacks. When the client establishes the connection to the network, the access point triggers a certificate exchange to authenticate its identity. DHCP Snooping alone does not help us limit the rate of MAC addresses learned, but DAI works with DHCP snooping , of course port security would have been a better answer for this to limit the number of MAC addresses learned via one port but in this scenario this is what we have . Double tagging - change native VLAN Vlan Hopping - deactivate DTP