企業のルーターがインターネットに接続されるたびに、DNS ポイズニングによってネットワーク トラフィックが危険にさらされています。ネットワーク チームは、承認されていない DNS サーバーがネットワーク クライアントに割り当てられていることを検出し、信頼できる DNS サーバーを設定してインシデントを修復しますが、インターネットへの露出後に問題が再び発生します。次のベスト プラクティスのうち、ルーターに実装する必要があるのはどれですか?
正解:A
DNS poisoning is a type of attack that exploits the vulnerabilities of the DNS protocol to redirect network traffic to malicious websites or servers12. DNS poisoning can affect both the DNS resolver cache and the DNS client cache, making it difficult to detect and remove12. One of the common ways that DNS poisoning can occur is when an attacker compromises the router and changes its DNS settings to point to a rogue DNS server12. This way, the router will assign the malicious DNS server to the network clients, and any DNS queries from the clients will be resolved by the attacker's server12. To prevent this type of attack, one of the best practices is to change the device's default password and use a strong and unique password for the router's administrative interface13. This will make it harder for the attacker to gain access to the router and modify its DNS settings13. Changing the device's default password is also a general security measure that should be applied to any router or network device, as many attackers exploit the fact that many users do not change the default credentials that come with the device34. Therefore, the correct answer is A. Change the device's default password, as this will help prevent DNS poisoning attacks and improve the overall security of the router and the network. Reference: 1: What is DNS poisoning and how to prevent it - BlueCat Networks 2: An Introduction to "DNS Poisoning" (And How to Prevent It) - Kinsta 3: The Best Router Settings for Home Networks - Lifewire 4: Recommended settings for Wi-Fi routers and access points