ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 301 - SY0-701 discussion

Report
Export

A recent penetration test identified that an attacker could flood the MAC address table of network switches. Which of the following would best mitigate this type of attack?

A.
Load balancer
Answers
A.
Load balancer
B.
Port security
Answers
B.
Port security
C.
IPS
Answers
C.
IPS
D.
NGFW
Answers
D.
NGFW
Suggested answer: B

Explanation:

Port security is the best mitigation technique for preventing an attacker from flooding the MAC address table of network switches. Port security can limit the number of MAC addresses learned on a port, preventing an attacker from overwhelming the switch's MAC table (a form of MAC flooding attack). When the allowed number of MAC addresses is exceeded, port security can block additional devices or trigger alerts.

Load balancer distributes network traffic but does not address MAC flooding attacks.

IPS (Intrusion Prevention System) detects and prevents attacks but isn't specifically designed for MAC flooding mitigation.

NGFW (Next-Generation Firewall) offers advanced traffic inspection but is not directly involved in MAC table security.

asked 02/10/2024
Aubrey Oliver Jr
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first