312-50 exam dumps

312-50 practice question 201 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 201

Single answer▪ Sniffing Tools

During an authorized internal assessment, you connect a laptop running Wireshark to an access switch port in the finance VLAN. You can capture only broadcast traffic and frames to or from your own MAC address, but the client wants you to inspect a specific workstation's unencrypted legacy protocol traffic without installing software on that workstation. Which action would be the most appropriate to enable effective packet capture for this task?

  1. A

    Configure a SPAN/mirror port on the switch and connect the sniffer to the mirrored port

  2. B

    Enable promiscuous mode in Wireshark so the NIC can capture all traffic on the switched network segment

  3. C

    Send ARP requests continuously from the laptop so the switch floods more unicast traffic to your port

  4. D

    Change the laptop's MAC address to match the target workstation so the switch forwards that host's traffic to your system

Show answer and explanation

Correct answer: A

Explanation

This question tests practical understanding of sniffing in switched environments. Tools such as Wireshark can capture only the traffic delivered to the network interface. In modern switched Ethernet networks, simply enabling promiscuous mode is not enough to see other hosts' unicast traffic because the switch forwards frames only to the appropriate port based on its MAC address table. The correct technique in an authorized assessment is to use switch-based traffic duplication such as SPAN/port mirroring, or alternatively a network TAP where available. This aligns with standard enterprise monitoring practices and vendor documentation from Cisco and other switch manufacturers describing SPAN/port mirroring for traffic analysis, IDS monitoring, and troubleshooting. The key CEH concept is that sniffing tools depend on network architecture: on hubs or shared media, promiscuous mode may be sufficient, but on switched networks you typically need a mirror port, TAP, or an active interception technique such as ARP poisoning when explicitly in scope. For a clean, non-intrusive, and authorized capture of a workstation's traffic, SPAN is the best answer.

  • A. Correct.

    Correct. On a switched Ethernet network, normal access ports receive broadcasts, multicasts, and unicast frames destined for that port's MAC address. To observe another host's traffic from a separate port without touching the endpoint, the standard and appropriate approach is to configure a SPAN (Switched Port Analyzer) or mirror port on the switch. This copies traffic from the target port or VLAN to the analyst's monitoring port, allowing Wireshark or another sniffer to capture the packets reliably.

  • B. Incorrect.

    Incorrect. Promiscuous mode allows the network interface and capture software to accept frames that reach the interface even if they are not addressed to that NIC. However, on a switched network, the switch does not normally forward other hosts' unicast traffic to your port in the first place. Promiscuous mode is useful on shared media or when traffic is already being delivered to the interface, but by itself it does not bypass switch forwarding logic.

  • C. Incorrect.

    Incorrect. Excess ARP traffic may generate additional broadcasts, but it will not cause the switch to flood unrelated unicast traffic from the target workstation to your port under normal operation. This reflects a common misconception that simply increasing broadcast or ARP activity makes a switch behave like a hub. It does not provide a controlled or reliable way to capture another host's traffic.

  • D. Incorrect.

    Incorrect. MAC spoofing to impersonate the target host is not the appropriate solution here. At best, it can create a MAC table conflict or disrupt connectivity; at worst, it can amount to an active attack such as traffic hijacking or denial of service. It also does not provide a clean, authorized, and stable method for passive monitoring during an assessment. The scenario specifically asks for the most appropriate action, and switch port mirroring is the standard defensive and assessment-friendly method.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam