199k views
5 votes
Which feature on a switch makes it vulnerable to VLAN hopping attacks?

a. MAC address filtering
b. VLAN trunking
c. Port security
d. Virtual LAN configuration

User Ayu
by
8.3k points

1 Answer

6 votes

Final answer:

The vulnerability that makes a switch susceptible to VLAN hopping attacks is VLAN trunking. Improper configuration of trunking can allow attackers to send packets that appear to be part of a less secure VLAN, gaining unauthorized access to network segments.

Step-by-step explanation:

The feature on a switch that makes it vulnerable to VLAN hopping attacks is b. VLAN trunking. VLAN trunking is a method used to carry traffic from multiple VLANs over a single physical link between two switches. In a VLAN hopping attack, an attacker takes advantage of the trunking protocol by sending packets to a switch with information suggesting that they belong to a certain VLAN, usually one with fewer security measures. When configured improperly, a switch can accept this traffic and forward it to the targeted VLAN, thereby allowing the attacker to bypass network segmentation and access restricted network segments.



Avoiding this type of attack includes proper configuration of native VLANs and ensuring that all unused ports are either disabled or assigned to a 'dummy' VLAN that has no resources. Implementing port security and other preventative measures can add an additional layer of defense, but they are not directly related to the vulnerability exploited in VLAN hopping.

User Scott Kennedy
by
8.2k points