312-50 exam dumps

312-50 practice question 183 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 183

Single answer▪ Sniffing Concepts

During an internal authorized assessment, you connect a laptop running Wireshark to an unused switch port in a modern corporate LAN. The network uses switched Ethernet, and your capture shows only broadcast traffic and packets to or from your own host. You need to observe traffic exchanged between a target workstation and the default gateway without installing software on either endpoint. Which technique would be the most effective to achieve this in the same VLAN?

  1. A

    Perform ARP spoofing/ARP poisoning so the target and gateway send traffic through the assessor's host

  2. B

    Send repeated ICMP echo requests to the gateway to force the switch to mirror traffic to your port

  3. C

    Use DNS cache poisoning to redirect the target workstation's traffic through the assessor's host

  4. D

    Enable DHCP starvation to make the switch flood unicast traffic to all ports

Show answer and explanation

Correct answer: A

Explanation

On switched Ethernet networks, passive sniffing is limited because the switch forwards unicast frames only to the port associated with the destination MAC address. As a result, an assessor connected to a standard access port usually sees broadcast traffic, multicast traffic, and frames addressed to the assessor's host. To capture traffic between two other devices in the same VLAN, the assessor generally needs either administrative help, such as configuring a SPAN/mirror port, or an active interception technique. When administrative reconfiguration is not available and software cannot be installed on endpoints, ARP spoofing is the most practical active sniffing method for IPv4 local segments. It abuses the stateless nature of ARP by sending forged ARP replies so systems update their ARP caches with the attacker's MAC address. Tools such as Ettercap and Bettercap have historically demonstrated this concept in lab and assessment settings. This aligns with common Ethernet and ARP behavior documented in vendor networking references and RFC 826 for ARP. Note that in real environments, defenses such as Dynamic ARP Inspection, static ARP entries for critical systems, network segmentation, and encrypted protocols can reduce the effectiveness and impact of sniffing attacks.

  • A. Correct.

    Correct. In a switched Ethernet environment, passive sniffing from a normal access port typically reveals only broadcast, multicast, and traffic destined for the local host. To observe another host's traffic in the same VLAN without endpoint agents, a common active sniffing method is ARP spoofing (also called ARP poisoning). By sending forged ARP replies, the assessor can convince the target that the assessor's MAC address belongs to the gateway and/or convince the gateway that the assessor's MAC belongs to the target. This places the assessor's system in the traffic path as a man-in-the-middle, allowing capture and forwarding of packets. This is a standard switched-LAN sniffing concept covered in CEH.

  • B. Incorrect.

    Incorrect. ICMP echo requests do not cause a switch to mirror unrelated traffic to another access port. Switch port mirroring, often called SPAN, must be configured on the switch by an administrator. Simply generating ICMP traffic may create additional packets involving your host and the gateway, but it will not make the switch forward third-party unicast traffic between the target workstation and the gateway to your interface.

  • C. Incorrect.

    Incorrect. DNS cache poisoning affects name resolution, not Layer 2 forwarding behavior between a host and its default gateway. While DNS manipulation can redirect users to malicious systems or alter where application-layer requests are sent, it does not generally place the assessor inline for all traffic between the workstation and gateway on a switched LAN. This option confuses application-layer redirection with sniffing techniques used to capture local Ethernet traffic.

  • D. Incorrect.

    Incorrect. DHCP starvation is an attack against DHCP address allocation, typically used to exhaust a DHCP server's pool so a rogue DHCP server can be introduced. It does not make a switch flood all unicast traffic to every port in a normal switched network. Unicast flooding is more closely associated with unknown CAM table conditions or MAC table issues, not DHCP pool exhaustion. This distractor reflects a common misconception that any LAN attack can be used for packet capture.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam