Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium
A network security administrator is analyzing traffic patterns to identify potential threats. They observe a significant increase in UDP traffic on port 161 destined for network devices, originating from an unauthorized internal host. This traffic is indicative of an attempt to gather information about network devices. Which type of threat is most likely occurring?
- AReconnaissance attack
- BMan-in-the-Middle (MitM) attack
- CDenial of Service (DoS) attack
- DSpoofing attack
Show answer & explanationAnswer & explanation
Correct answer: A. Reconnaissance attack
UDP port 161 is commonly used by SNMP. A large volume of SNMP requests from an unauthorized host suggests a reconnaissance attack, where an attacker is attempting to discover network device configurations, status, and topology for potential future exploits.
Why the other options are wrong
- B. MitM involves intercepting and altering communication, not just information gathering via SNMP.
- C. DoS aims to disrupt service, not primarily gather information.
- D. Spoofing involves faking identity, which might be part of reconnaissance, but the primary activity described is information gathering.
Reconnaissance Attack
The preparatory phase of an attack where an attacker gathers information about a target network, system, or organization.
- Aims to map network, identify vulnerabilities, discover services.
- Often uses tools like Nmap, SNMP queries, DNS lookups, port scans.
- Precedes exploitation phase.
Memory trick: Attackers first 'look around,' then 'break in,' then 'take control.'