エンドポイント ログは、マシンが DHCP 経由で異常なゲートウェイ アドレスと異常な DNS サーバーを取得したことを示しています。どのタイプの攻撃が発生していますか?
正解:B
The situation where endpoint logs show a machine receiving an unusual gateway address and DNS servers via DHCP is indicative of a Man-in-the-Middle (MitM) attack, specifically a DHCP spoofing attack. In this type of attack, an adversary can set up a rogue DHCP server or manipulate the DHCP communication to provide false gateway and DNS information to clients. This allows the attacker to intercept, monitor, or manipulate traffic between the client and the intended gateway or DNS servers2.