exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 636 discussion

Actual exam question from CompTIA's SY0-601
Question #: 636
Topic #: 1
[All SY0-601 Questions]

A security analyst is investigating an incident that was first reported as an issue connecting to network shares and the Internet. While reviewing logs and tool output, the analyst sees the following:



Which of the following attacks has occurred?

  • A. IP conflict
  • B. Pass-the-hash
  • C. MAC flooding
  • D. Directory traversal
  • E. ARP poisoning
Show Suggested Answer Hide Answer
Suggested Answer: E 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JT4
Highly Voted 1 year, 9 months ago
Selected Answer: E
Address Resolution Protocol (ARP) resolves IPv4 addresses to MAC addresses. MAC addresses are the physical addresses or hardware addresses. TCP/IP uses the IP address to get a packet to a destination network. ARP poisoning attacks use ARP packets to give clients false hardware address updates, and attackers use them to redirect or interrupt network traffic
upvoted 12 times
...
johnabayot
Highly Voted 1 year, 4 months ago
Selected Answer: E
E. ARP poisoning. Some clues that indicate ARP poisoning are: Multiple IP addresses are associated with the same MAC address in the ARP table, as shown in the question. The MAC address of the gateway or the DNS server is changed to the attacker’s MAC address.
upvoted 7 times
...
xBrynlee
Most Recent 12 months ago
Selected Answer: E
ARP poisoning: redirecting an IP address to MAC address of a computer that is not the intended recipient. This attack is directed at HOSTS. DNS poisoning is a variation of ARP where the switch's cache table has random sources of MAC addresses. This attack is directed on the network SWITCH. We see in the question that the users are the ones having issues, so the answer is E. ARP poisoning
upvoted 1 times
...
Malkhofash
1 year, 5 months ago
ARP poisoning
upvoted 2 times
...
wreckitralphhhhhh
1 year, 6 months ago
The information presented here shows IP addresses paired with their corresponding MAC (Media Access Control) addresses. Based on this, the scenario appears to exhibit MAC address duplication for different IP addresses, specifically, 10.0.0.1 and 10.0.0.115 having the same MAC address (00-18-21-ad-24-bc). This situation suggests an anomaly known as MAC flooding, which occurs when an attacker overloads the switch's MAC table, associating multiple MAC addresses with a single port. As a result, traffic intended for different devices gets directed to a single port, which can lead to network performance issues or potential security threats. Therefore, the correct answer is C. MAC flooding.
upvoted 3 times
MortG7
1 year, 5 months ago
What you do not realize is you just defined ARP poisoning and called it MAC flooding. E
upvoted 11 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...