312-50 exam dumps

312-50 practice question 194 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 194

Single answer▪ Sniffing Technique: Spoofing Attacks

During an internal penetration test on a switched corporate LAN, you are connected to the same subnet as a legacy file server and several Windows clients. Your goal is to capture authentication traffic for a sanctioned assessment without directly exploiting any host. You notice that the switch has no DHCP snooping or Dynamic ARP Inspection enabled. Which technique would most effectively allow you to intercept traffic between a target client and the default gateway by abusing a spoofing attack on the local network?

  1. A

    Perform ARP spoofing to poison the client and gateway ARP caches so both systems map each other's IP address to your MAC address

  2. B

    Send forged DNS replies to the client so the default gateway hostname resolves to your attack system

  3. C

    Use IP spoofing to craft packets with the gateway's source IP and wait for the switch to mirror the traffic to your port

  4. D

    Flood the switch CAM table until it reboots, causing all packets to be broadcast to every host on the subnet

Show answer and explanation

Correct answer: A

Explanation

The most effective local spoofing-based sniffing method in this scenario is ARP spoofing. On IPv4 Ethernet networks, hosts rely on ARP to map IP addresses to MAC addresses. Because ARP is stateless and unauthenticated, an attacker on the same broadcast domain can send forged ARP replies to poison the caches of both the victim and the gateway, positioning the attack system as a man-in-the-middle. This is a standard CEH-relevant sniffing and spoofing technique used to capture credentials, session data, or other traffic during authorized assessments. Defensive controls that mitigate this include Dynamic ARP Inspection, DHCP snooping, static ARP entries for critical systems in limited cases, port security, and use of encrypted protocols to reduce the value of captured traffic. This aligns with well-established vendor guidance from Cisco and common ARP protocol behavior described in RFC 826.

  • A. Correct.

    Correct. ARP spoofing, also called ARP cache poisoning, is a classic man-in-the-middle technique on local Ethernet networks. By sending forged ARP replies to both the victim and the default gateway, the attacker associates the victim's IP and the gateway's IP with the attacker's MAC address. Traffic is then forwarded through the attacker's system, enabling packet capture and relaying. This is especially effective when protections such as Dynamic ARP Inspection are absent.

  • B. Incorrect.

    Incorrect. DNS spoofing can redirect a client to a malicious destination for specific hostname-based connections, but it does not place the attacker inline between a client and the default gateway at Layer 2. It affects name resolution, not the ARP-based MAC-to-IP mapping needed to intercept general subnet traffic.

  • C. Incorrect.

    Incorrect. IP spoofing falsifies the source IP in packets, but it does not cause a switch to forward other hosts' traffic to the attacker. Switches make forwarding decisions based on MAC addresses and CAM tables, not on the source IP field alone. IP spoofing is useful in other attack scenarios, but not for establishing a local man-in-the-middle position on a switched LAN.

  • D. Incorrect.

    Incorrect. CAM table flooding can, on some older or poorly configured switches, force fail-open behavior resembling a hub, but 'until it reboots' is inaccurate and the technique is unreliable compared to ARP spoofing for targeted interception. Modern switches often mitigate MAC flooding, and the scenario specifically highlights missing ARP protections, pointing to ARP poisoning as the practical approach.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam