312-50 exam dumps

312-50 practice question 185 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 185

Single answer▪ Sniffing Technique: MAC Attacks

During an authorized internal assessment, you connect a laptop to an access-layer switch in a corporate office. The switch port is configured as a standard access port with no port-security features enabled. You need to determine whether the network is vulnerable to a sniffing technique based on MAC attacks that could allow traffic interception beyond your own host. Which action would most likely demonstrate this weakness?

  1. A

    Flood the switch CAM table with frames containing many spoofed source MAC addresses until the switch begins forwarding traffic out all ports like a hub

  2. B

    Send forged ARP replies to map the default gateway IP address to your MAC address and wait for the switch to mirror all VLAN traffic to your port

  3. C

    Transmit DHCPDISCOVER packets with random client MAC addresses until the switch disables the port and enters err-disabled state

  4. D

    Craft 802.1Q double-tagged frames so the switch permanently learns your NIC as the trunk uplink for every VLAN

Show answer and explanation

Correct answer: A

Explanation

The best answer is the CAM table flooding attack, often called MAC flooding. In switched Ethernet, the switch learns source MAC-to-port mappings in its CAM table and forwards frames only to the port where the destination MAC is known. If an attacker overflows that table with many bogus source MAC addresses, the switch may treat legitimate destinations as unknown unicasts and flood frames out multiple ports, creating an opportunity to sniff traffic. In practice, modern managed switches often mitigate this with port security, limiting the number of MAC addresses per port, sticky MAC learning, storm control, and monitoring for CAM overflow behavior. ARP spoofing is also a common Layer 2 interception method, but it is a different attack category from MAC flooding. Relevant best practices and vendor guidance typically include enabling switch port-security features, restricting learned MAC addresses, disabling unused ports, and using monitoring and logging to detect anomalous MAC churn.

  • A. Correct.

    Correct. This describes MAC flooding, a classic CAM table overflow attack against a switch. By sending frames with many fake source MAC addresses, an attacker attempts to exhaust the switch's CAM (Content Addressable Memory) table. When the switch can no longer map destination MAC addresses to specific ports, some switches may fail open and flood unknown unicast traffic out multiple ports, enabling sniffing of traffic not originally destined for the attacker's host. This is the MAC attack most directly associated with switch-based sniffing weaknesses.

  • B. Incorrect.

    Incorrect. Forged ARP replies describe ARP spoofing/poisoning, which is a Layer 2 man-in-the-middle technique, not a MAC flooding attack against the switch's CAM table. ARP poisoning can redirect selected traffic through the attacker, but it does not cause the switch to mirror all VLAN traffic to the attacker's port. The misconception is confusing ARP-based interception with CAM-table-based sniffing.

  • C. Incorrect.

    Incorrect. Sending DHCPDISCOVER packets with changing MAC addresses is characteristic of DHCP starvation, which targets the DHCP server's address pool rather than the switch CAM table. While random MAC addresses are involved, the purpose is to exhaust IP leases, not to make the switch flood unknown unicast frames for sniffing. Port err-disable behavior would depend on security controls and is not the defining outcome of this attack.

  • D. Incorrect.

    Incorrect. Double tagging is a VLAN hopping technique that can, under specific misconfigurations, allow traffic injection into another VLAN. It does not cause the switch to relearn the attacker's NIC as the trunk uplink for every VLAN, and it is not the standard method for demonstrating a sniffing weakness based on MAC attacks. This option mixes VLAN hopping concepts with invalid switch learning behavior.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam