SSCP Systems Security Certified PractitionerNetwork and Communications SecurityHard
A security auditor discovers that a company's internal network uses unmanaged switches and is susceptible to Layer 2 attacks, such as MAC flooding and ARP poisoning. Which of the following security controls would most effectively mitigate these types of attacks?
- AEnforcing strong password policies for all network devices.
- BDeploying an intrusion prevention system (IPS) at the network perimeter.
- CUtilizing managed switches with features like DHCP snooping and dynamic ARP inspection.
- DImplementing a next-generation firewall (NGFW).
Show answer & explanationAnswer & explanation
Correct answer: C. Utilizing managed switches with features like DHCP snooping and dynamic ARP inspection.
MAC flooding and ARP poisoning are Layer 2 attacks. Managed switches with features like DHCP snooping (to prevent rogue DHCP servers and validate IP-to-MAC bindings) and Dynamic ARP Inspection (DAI) (to validate ARP packets) are specifically designed to mitigate these vulnerabilities by enforcing Layer 2 security.
Why the other options are wrong
- A. Strong password policies are crucial for device access but do not prevent MAC flooding or ARP poisoning attacks themselves.
- B. An IPS at the perimeter protects the network from external threats but generally does not address internal Layer 2 vulnerabilities effectively.
- D. NGFWs primarily operate at Layer 3 and above, providing limited protection against Layer 2 specific attacks like MAC flooding or ARP poisoning.
Layer 2 Security Features
Security controls implemented on network switches to protect against vulnerabilities specific to the data link layer (Layer 2) of the OSI model.
- Protects against MAC flooding, ARP poisoning, VLAN hopping.
- Includes features like DHCP snooping, Dynamic ARP Inspection (DAI), Port Security.
- Requires managed switches for implementation.
Memory trick: Layers Need Specific Defenses.