ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityHard

A security auditor discovers that several network switches in a critical infrastructure environment are configured with default administrative credentials and unencrypted management protocols. The auditor recommends immediate action to prevent unauthorized access and manipulation of network traffic. Which network attack is most directly facilitated by these vulnerabilities?

  1. AMan-in-the-Middle (MITM)
  2. BRoute Poisoning
  3. CEavesdropping
  4. DDistributed Denial of Service (DDoS)
Show answer & explanation

Correct answer: A. Man-in-the-Middle (MITM)

Default credentials and unencrypted management protocols on switches allow an attacker to gain unauthorized control over the switch. With control, the attacker can reconfigure routing, ARP tables, or port mirroring to intercept, alter, or redirect traffic, which are hallmarks of a Man-in-the-Middle attack.

Why the other options are wrong

  • B. Route poisoning manipulates routing tables to cause traffic blackholing or loops, which is a specific type of traffic manipulation that an MITM attacker with switch access could perform.
  • C. Eavesdropping (sniffing) is a component of many attacks, but gaining administrative control over a switch allows for more active manipulation, not just passive listening.
  • D. DDoS attacks aim to overwhelm a target; while compromised devices could be part of a botnet, the direct vulnerability described (management access) leads more directly to traffic manipulation.

Man-in-the-Middle (MITM) Attack

An attack where the attacker secretly relays and possibly alters the communication between two parties who believe they are directly communicating with each other.

  • Requires the attacker to intercept and control the communication path.
  • Can be facilitated by ARP spoofing, DNS spoofing, or compromised network devices.
  • Compromises confidentiality and integrity.

Memory trick: A 'Compromised Switch' makes the 'Attacker' the 'Man in the Middle'.

More Communication and Network Security questions