SSCP Systems Security Certified PractitionerNetwork and Communications SecurityHard

A security auditor discovers that a company's internal network uses unmanaged switches and is susceptible to Layer 2 attacks, such as MAC flooding and ARP poisoning. Which of the following security controls would most effectively mitigate these types of attacks?

  1. AEnforcing strong password policies for all network devices.
  2. BDeploying an intrusion prevention system (IPS) at the network perimeter.
  3. CUtilizing managed switches with features like DHCP snooping and dynamic ARP inspection.
  4. DImplementing a next-generation firewall (NGFW).
Show answer & explanation

Correct answer: C. Utilizing managed switches with features like DHCP snooping and dynamic ARP inspection.

MAC flooding and ARP poisoning are Layer 2 attacks. Managed switches with features like DHCP snooping (to prevent rogue DHCP servers and validate IP-to-MAC bindings) and Dynamic ARP Inspection (DAI) (to validate ARP packets) are specifically designed to mitigate these vulnerabilities by enforcing Layer 2 security.

Why the other options are wrong

  • A. Strong password policies are crucial for device access but do not prevent MAC flooding or ARP poisoning attacks themselves.
  • B. An IPS at the perimeter protects the network from external threats but generally does not address internal Layer 2 vulnerabilities effectively.
  • D. NGFWs primarily operate at Layer 3 and above, providing limited protection against Layer 2 specific attacks like MAC flooding or ARP poisoning.

Layer 2 Security Features

Security controls implemented on network switches to protect against vulnerabilities specific to the data link layer (Layer 2) of the OSI model.

  • Protects against MAC flooding, ARP poisoning, VLAN hopping.
  • Includes features like DHCP snooping, Dynamic ARP Inspection (DAI), Port Security.
  • Requires managed switches for implementation.

Memory trick: Layers Need Specific Defenses.

More Network and Communications Security questions