ExamGecko
Question list
Search
Search

Related questions











Question 298 - 200-201 discussion

Report
Export

Endpoint logs indicate that a machine has obtained an unusual gateway address and unusual DNS servers via DHCP Which type of attack is occurring?

A.

command injection

Answers
A.

command injection

B.

man in the middle attack

Answers
B.

man in the middle attack

C.

evasion methods

Answers
C.

evasion methods

D.

phishing

Answers
D.

phishing

Suggested answer: B

Explanation:

The situation where endpoint logs show a machine receiving an unusual gateway address and DNS servers via DHCP is indicative of a Man-in-the-Middle (MitM) attack, specifically a DHCP spoofing attack. In this type of attack, an adversary can set up a rogue DHCP server or manipulate the DHCP communication to provide false gateway and DNS information to clients.This allows the attacker to intercept, monitor, or manipulate traffic between the client and the intended gateway or DNS servers2.

asked 07/10/2024
Malik Spamu
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first