Analyzing Traffic Flashcards

(17 cards)

1
Q

What is packet sniffing?

A

Collecting packets passing through a network to analyze or monitor them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the two main types of packet sniffing?

A

Active and Passive sniffing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What differentiates active from passive sniffing?

A

Active sniffing involves interaction with the target, while passive does not.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Give examples of active sniffing attacks.

A

ARP spoofing, MAC flooding, HTTPS/SSH spoofing, DNS spoofing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Where is passive sniffing typically carried out?

A

Hub-based or wireless networks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the function of a hardware packet sniffer?

A

Designed to examine network segments by being plugged directly into the network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the uses of legitimate packet sniffing?

A

Troubleshooting, application performance monitoring, security analysis, and traffic trend monitoring.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which protocols are common targets for packet sniffing attacks?

A

FTP, HTTP, SMTP, NNTP, POP, IMAP, Telnet.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How can you mitigate packet sniffing attacks?

A

Use encrypted protocols for network communication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What information is typically found in DHCP logs?

A

MAC addresses of devices that connected to a router.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What can you determine from Windows Event Viewer regarding network activity?

A

Detailed records of DHCP assignments and connection events.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which macOS utility is used to manage wireless networks?

A

AirPort Utility.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What evidence is available from an iOS device regarding Wi-Fi networks?

A

SSID, authentication type, MAC address of AP, timestamps of last connections.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What database in Android contains detailed network connection info?

A

Herrevad database.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does WIGLE.NET provide?

A

Central database of wireless network locations worldwide.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a rogue access point?

A

An unauthorized wireless access point installed on a secure network.

17
Q

Name two tools used for packet sniffing.

A

Wireshark and Kismet.