Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Network Basics and Security

A company secretary reviewing a data-breach incident at Sharma Fintech finds that an attacker captured data frames on the local Ethernet segment by spoofing MAC address mappings (ARP spoofing). At which OSI layer does the core weakness exploited lie, and which provision of Indian law is most directly attracted for unauthorised access to the system?

The weakness lies at the data link layer, since ARP spoofing manipulates MAC address mappings within the local segment. Unauthorised access to a computer system attracts Section 43 of the IT Act, 2000, with Section 66 for the criminal offence when done dishonestly or fraudulently.

  1. ANetwork layer; Section 43 read with Section 66 of the IT Act, 2000
  2. BData link layer; Section 43 read with Section 66 of the IT Act, 2000Correct
  3. CData link layer; Section 69A of the IT Act, 2000
  4. DTransport layer; Section 72 of the IT Act, 2000

Explanation

ARP resolves IP to MAC addresses and the resulting spoofing exploits trust at the data link layer (Layer 2), within a LAN. Unauthorised access and dishonest or fraudulent damage are covered by Section 43 with penal Section 66. Section 69A concerns blocking public access to information, and Section 72 concerns breach of confidentiality by persons with powers under the Act.

Did you get it right without looking?

One question tells you little. A timed set on Network Basics and Security shows your real accuracy, how long you take and where you lose marks.

More Network Basics and Security questions