Question:
Which type of VLAN-hopping attack may be prevented by designating an unused VLAN as the native VLAN?
- DHCP spoofing
- DHCP starvation
- VLAN double-tagging
- DTP spoofing
Explanation: Spoofing DTP messages forces a switch into trunking mode as part of a VLAN-hopping attack, but VLAN double tagging works even if trunk ports are disabled. Changing the native VLAN from the default to an unused VLAN reduces the possibility of this type of attack. DHCP spoofing and DHCP starvation exploit vulnerabilities in the DHCP message exchange.
Exam with this question: CCNA 2 v7 Checkpoint Exam: L2 Security and WLANs Exam Answers
Exam with this question: CCNA Security Chapter 6 Exam Answers
Exam with this question: CCNA Security Practice Final Exam Answers
Please login or Register to submit your answer