Skip to content
ScopefileGet the app

Technique fileSniffing

Layer 2 attacks and the switch feature that blocks each

Layer-2 attacks abuse the switch and the local network: MAC flooding, ARP poisoning, DHCP starvation, DHCP spoofing and VLAN hopping. Each has a matching switch feature: port security, Dynamic ARP Inspection, DHCP snooping or locked-down trunking.

Exam
312-50
Domain
4 · Network & perimeter
Targets
8

What each attack abuses

These sit in the Sniffing module, and the payoff is a lookup table more than deep theory. Group the attacks by what they abuse: the switch's MAC address table (MAC flooding), the address mappings hosts keep in their ARP caches (ARP poisoning), address assignment (DHCP starvation and spoofing), or segmentation (VLAN hopping).

Every defense lives on the switch at the access layer, close to where the attacker plugs in. That is why Layer-2 hardening is a configuration job for the network team rather than something endpoints can fix on their own.

Attack against switch feature

Each Layer-2 attack and the control that blocks it
AttackWhat it abusesSwitch feature
MAC floodingThe switch's MAC address tablePort security
ARP poisoningTrust in unsolicited ARP repliesDynamic ARP Inspection (DAI)
DHCP starvationThe finite pool of leasesPort security; DHCP snooping rate limits
DHCP spoofingClients trusting any DHCP answerDHCP snooping trusted ports
VLAN hoppingAutomatic trunk negotiation and taggingDisable auto-trunking; set access ports explicitly

Neighbors in the same module

STP manipulation
A rogue device claims to be the best root bridge and pulls traffic through itself. BPDU guard and root guard on access ports block it.
DNS poisoning
Plants false name-to-address answers so clients reach the wrong host. DNSSEC and hardened resolvers counter it.
Promiscuous-mode detection
Defenders look for interfaces that accept every frame on the wire, a sign of a sniffer on the segment.

Switch-side fixes

A mix of attack definitions and detection calls.

Answered 0/8Hits 0

T-01

What attack technique involves sending forged ARP messages to associate an attacker's MAC address with the IP address of a legitimate host?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AMAC flooding overwhelms a switch's address table with fake source addresses, rather than forging ARP replies.
  2. BDNS spoofing falsifies name resolution answers, which works at the application layer rather than through ARP.
  3. CIP fragmentation attacks abuse how packets are split and reassembled, not how IP addresses map to MAC addresses.
  4. DCorrect: ARP poisoning sends forged ARP replies so traffic for a legitimate IP address goes to the attacker's MAC, enabling man-in-the-middle interception.
T-02

What attack involves sending numerous MAC addresses to a switch to overflow its MAC address table?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AMAC duplication means cloning one specific legitimate address, rather than flooding the switch with many addresses.
  2. BCorrect: MAC flooding fills the switch's CAM table with bogus addresses so it fails open and floods frames to all ports like a hub.
  3. CCAM table poisoning is not the standard term; filling the table with bogus entries is called MAC flooding.
  4. DSwitch spoofing tricks a switch into forming a trunk with the attacker, which is a VLAN hopping technique.
T-03

Which technology helps prevent MAC flooding attacks on network switches?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA VPN encrypts traffic between endpoints but does nothing to limit how many MAC addresses a switch port learns.
  2. BNetwork address translation rewrites IP addresses at routers and has no bearing on a switch's MAC address table.
  3. CVLAN trunking carries multiple VLANs over one link and can itself be abused, so it does not prevent MAC flooding.
  4. DCorrect: port security limits how many MAC addresses a switch port can learn and shuts down or restricts the port when the limit is exceeded.
T-04

A determined insider successfully bypassed static MAC limiting by spoofing the address of an already-trusted workstation. Which comprehensive access-layer configuration would best prevent this specific evasion technique?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: 802.1X authenticates the device itself instead of trusting its MAC address, while DHCP snooping and Dynamic ARP Inspection validate the bindings it uses afterward.
  2. BStorm control limits floods of broadcast or multicast traffic, while a single spoofed trusted MAC generates normal traffic levels and passes untouched.
  3. CStatic routing and IPS tools work above the access layer and cannot tell that a trusted MAC address now belongs to an impostor's device.
  4. DPort security and VLAN tagging still rely on MAC addresses, which the insider already spoofed, so they repeat the same weakness that was bypassed.
T-05

Which attack attempts to cause a DHCP server to lease all available IP addresses, preventing legitimate users from obtaining network access?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAddress harvesting is not a standard name for this attack and usually refers to collecting email addresses.
  2. BCorrect: DHCP starvation floods the server with requests from spoofed MAC addresses until the address pool is empty, which DHCP snooping and port security limit.
  3. CDHCP spoofing means running a rogue DHCP server that hands out malicious settings, which often follows starvation but is a different attack.
  4. DIP exhaustion describes the result, an empty address pool, but the recognized attack name is DHCP starvation.
T-06

Which network attack involves forging DHCP responses to direct clients to a malicious DNS server or gateway?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AARP cache poisoning redirects traffic by forging MAC-to-IP mappings, not by answering DHCP requests.
  2. BVLAN hopping lets traffic escape its VLAN through trunking or double tagging, rather than altering client network settings.
  3. CCorrect: DHCP spoofing uses a rogue DHCP server to hand clients a malicious gateway or DNS server, which DHCP snooping blocks on untrusted ports.
  4. DDNS hijacking tampers with name resolution directly, whereas the stem describes forged DHCP replies that assign a malicious resolver.
T-07

A security log reveals multiple gratuitous ARP broadcasts on a subnet. Which specific pattern definitively distinguishes an active ARP spoofing attack from a legitimate high-availability cluster failover event?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ARepeated announcements for a single IP look like a normal host update, not the signature of cache poisoning.
  2. BReverse-ARP lookups are a legitimate address-resolution pattern unrelated to spoofing.
  3. CCorrect: one MAC address repeatedly claiming several different IPs, such as a gateway and a victim, is the hallmark of ARP cache poisoning rather than a clean failover.
  4. DA virtual IP moving between two MAC addresses is exactly how legitimate high-availability failover behaves.
T-08

What attack allows an attacker to jump from one VLAN to another despite VLAN segregation?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: VLAN hopping uses switch spoofing or double tagging to reach traffic on another VLAN; disabling auto-trunking and changing the native VLAN prevent it.
  2. BA rogue DHCP server hands out malicious network settings rather than crossing VLAN boundaries.
  3. CDHCP starvation exhausts a server's address pool and does not move traffic between VLANs.
  4. DMAC flooding overflows a switch's address table to cause frame flooding within a VLAN, rather than jumping between VLANs.

Inside the switch

Why does a flooded switch help a sniffer?

When its address table fills, a switch can no longer tell which port a frame belongs to and sends traffic out of many ports at once. A sniffer on any of those ports then sees conversations it was never meant to see.

What does IP Source Guard add?

It drops traffic whose source address does not match the binding recorded for that port, which stops a host from simply claiming someone else's IP address.

Is a VLAN a security boundary?

Only when trunking and tagging are locked down. With automatic trunk negotiation left on, an attacker's port can talk its way onto other VLANs, which is what VLAN hopping exploits.