312-50 exam dumps

312-50 practice question 205 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 205

Single answer▪ Sniffing Detection Techniques

During an internal security assessment, you suspect a workstation on the same switched Ethernet segment as your test laptop has been placed into promiscuous mode to capture other users' traffic. You want to use an active sniffing detection technique from your laptop that can help identify a host behaving like a packet sniffer on the local network. Which action is the MOST appropriate?

  1. A

    Send a crafted ARP request with a non-broadcast destination MAC address and watch for replies from hosts that should normally ignore it

  2. B

    Run a full TCP connect scan against all hosts and identify the one with the largest number of open ports

  3. C

    Send oversized ICMP echo requests to all hosts and identify the one that fragments the packets incorrectly

  4. D

    Query the switch CAM table and identify any host that has learned more than one MAC address on a single access port

Show answer and explanation

Correct answer: A

Explanation

In CEH-style network analysis, sniffing detection techniques often distinguish between passive observation and active probing for promiscuous mode behavior. On switched Ethernet, passive sniffing is harder because traffic is normally only forwarded to the intended port, so detecting a sniffer often involves sending crafted packets and looking for abnormal responses. ARP-based and specially addressed frame tests are commonly cited active methods because a host in promiscuous mode may inspect and sometimes respond to traffic that a normal NIC would drop at Layer 2. By contrast, generic port scanning, fragmentation tests, or switch CAM-table reviews may be useful for other security tasks but are not the best direct method for identifying a sniffing host. Best practice is to combine such testing with switch port security, DHCP snooping, Dynamic ARP Inspection, 802.1X, and encrypted protocols such as SSH, TLS, and IPsec to reduce both the opportunity and impact of sniffing.

  • A. Correct.

    Correct. A classic active sniffing detection approach is to send deliberately crafted frames, such as ARP requests with unusual Layer 2 addressing, to see whether a host in promiscuous mode processes and responds to traffic it should normally discard. A NIC operating normally should ignore frames not addressed to its MAC address (except broadcasts/multicasts as appropriate). A response can indicate that the interface or capture stack is accepting packets beyond normal filtering.

  • B. Incorrect.

    Incorrect. A TCP connect scan may reveal exposed services, but the number of open ports has no reliable relationship to whether a host is sniffing traffic. This distractor reflects the common misconception that 'more services' implies 'more suspicious behavior.' Sniffing detection focuses on packet-handling behavior, not general service exposure.

  • C. Incorrect.

    Incorrect. Oversized ICMP echo tests are more relevant to MTU, fragmentation, or protocol-stack robustness issues. Improper fragmentation behavior does not specifically indicate promiscuous mode or packet capture activity. Someone might choose this because it sounds like a low-level network test, but it is not a recognized technique for detecting sniffers.

  • D. Incorrect.

    Incorrect. Reviewing the switch CAM/MAC address table can help detect certain Layer 2 anomalies such as unauthorized bridging, MAC flooding effects, or devices acting like small switches, but it does not directly identify a host simply running a sniffer in promiscuous mode. A standard sniffer on an endpoint usually does not cause the switch to learn multiple MAC addresses on that port.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam