Protocol analysis for a transit-yard WLAN shows unusual deauthentication spikes that correlate with sudden client drops. Which detection conclusion is most appropriate?
Select an answer to reveal the explanation.
Short Explanation
Lots of “get off my AP” frames right when laptops fall offline is the smoking gun for a deauth flood. Your wireless analyzer or WIPS is doing its job by tying the spike to the drops. DNS firewall rules do not invent 802.11 deauths.
Full Explanation
Detecting deauthentication DoS uses wireless protocol analytics or WIDS/WIPS that count management-frame anomalies and correlate them with client disconnects. Elevated deauth rates are a primary indicator of availability attacks that may also precede handshake capture. Wired firewall DNS behavior does not manifest as 802.11 deauthentication frames.