How can organizations detect an evil-twin attack?
What is a common indicator of a jamming attack?
What might indicate an ARP poisoning attack?
What is a sign of a MAC flooding attack?
What might prompt an organization to investigate DNS poisoning?
What are examples of network-based indicators of compromise (IoCs)?
A security team notices that no devices in a specific area are connecting to Wi-Fi, and EM noise is detected in the wireless range. What type of attack might be occurring?
A network administrator finds duplicate MAC addresses in ARP packets and unusual entries in the ARP table. What type of attack is likely underway?
A switch shows a sudden surge of Ethernet frames, each with a different MAC address. What type of attack does this suggest?
A company’s website experiences a sharp drop in traffic without any changes to content or hosting. What should the security team investigate?