312-50 exam dumps

312-50 practice question 202 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 202

Select 3▪ Sniffing Countermeasures

A security team discovers that an attacker connected a rogue device to an open wall port in a finance department and used ARP spoofing to capture unencrypted internal traffic from nearby hosts. The organization wants to reduce the risk of similar sniffing attacks on its switched LAN without redesigning the entire network. Which combination of controls would be the MOST effective countermeasure?

  1. A

    Enable Dynamic ARP Inspection (DAI) and DHCP snooping on access switches

  2. B

    Configure port security on access switch ports to limit and bind allowed MAC addresses

  3. C

    Disable DNS recursion on internal DNS servers

  4. D

    Require encrypted protocols such as HTTPS, SSH, and SNMPv3 instead of cleartext alternatives

  5. E

    Increase the switch CAM table size to reduce flooding risk

Show answer and explanation

Correct answers: A, B, D

Explanation

The best answer is the combination of options 1, 2, and 4 because the scenario involves two practical issues: unauthorized network access through an open port and traffic interception through ARP spoofing. On switched networks, sniffing is commonly enabled by man-in-the-middle techniques such as ARP poisoning rather than simple passive listening. Dynamic ARP Inspection, especially when paired with DHCP snooping, is a well-established Layer 2 defense against forged ARP messages. Port security helps prevent rogue systems from connecting to unused access ports in the first place. Finally, using encrypted application and management protocols ensures that even if traffic is intercepted, sensitive contents and credentials are not exposed. These are aligned with common enterprise hardening guidance from network vendors such as Cisco for switch security features and with industry best practices favoring encrypted protocols over legacy cleartext services.

  • A. Correct.

    Correct. Dynamic ARP Inspection helps mitigate ARP spoofing/poisoning by validating ARP packets against trusted bindings, typically learned through DHCP snooping. DHCP snooping builds a binding table of legitimate IP-to-MAC-to-port mappings, and DAI uses that information to reject forged ARP replies. This directly addresses the attack described, where the rogue device used ARP spoofing to intercept traffic on a switched network.

  • B. Correct.

    Correct. Port security on access ports reduces the likelihood that a rogue device can simply plug into an unused wall jack and participate on the network. By limiting the number of MAC addresses per port and optionally statically or dynamically binding approved MAC addresses, the switch can shut down or restrict a port when an unauthorized device appears. This is a practical countermeasure against unauthorized network access that enables sniffing attacks.

  • C. Incorrect.

    Incorrect. Disabling DNS recursion can reduce certain DNS abuse scenarios, especially on public-facing resolvers, but it does not address sniffing on a LAN or ARP spoofing between local hosts. A candidate might choose this option because it sounds like a general hardening measure, but it is not relevant to preventing packet capture through local man-in-the-middle techniques.

  • D. Correct.

    Correct. Even if an attacker gains a position to observe traffic, enforcing encrypted protocols significantly reduces the value of captured packets. Replacing cleartext services such as HTTP, Telnet, FTP, and older SNMP versions with HTTPS, SSH, SFTP/FTPS, and SNMPv3 helps protect confidentiality. This is a core sniffing countermeasure because it prevents credential and data disclosure from passive or active interception.

  • E. Incorrect.

    Incorrect. Increasing CAM table size is not a standard or primary countermeasure for sniffing attacks. CAM table flooding attacks attempt to overflow a switch's forwarding table so it behaves more like a hub, but simply increasing table size does not reliably prevent abuse and does nothing specific against ARP spoofing. Proper controls include port security, storm control, segmentation, and validation features such as DAI rather than relying on table size changes.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam