Skip to content
ScopefileGet the app

Module 8Domain 4 of 9Network and Perimeter Hacking

Sniffing: what a capture reveals and how switches fight back

Sniffing means capturing the traffic that crosses a network segment and reading what it carries. Module 8 of CEH v13 spends little time on the capture itself: its weight sits on the attacks that push a switched network into delivering frames to the wrong port, and on the switch feature that refuses each one.

Exam
312-50
Domain
4 of 9
Domain weight
24%
This file
~5%
Targets
17

What a capture exposes, and why switches changed the game

A network interface normally discards frames addressed to other machines. Put it in promiscuous mode and it hands every frame it receives up to the capture software. The same capability runs intrusion-detection sensors, troubleshooting and forensics, so the module treats sniffing as dual-use: in an engagement, capture starts only after the client signs rules of engagement that name the segments, the time window and how captured data is stored and destroyed.

What leaks: anything sent in cleartext (credentials, file contents, mail), session tokens that ride unprotected, and metadata that survives encryption: who talks to whom, when, and how much. Stolen tokens are where sniffing hands off to network-level session hijacking.

Passive vs active sniffing

Passive sniffing works on shared media such as a hub or an open wireless cell, where every station already receives every frame. Nothing is sent, so there is little to detect. Active sniffing is what a switched network forces: a switch forwards each frame only to the port that owns the destination address, so an attacker has to tamper with the switch's table, with host address mappings, or with DHCP and DNS to pull traffic toward themselves. Every active technique changes something on the network, and that change is what defenders alert on.

Spotting a sniffer

A purely passive listener is hard to find; detection aims at two things instead. First, hosts whose interface is in promiscuous mode, found by probes that only such an interface would answer. Second, the side effects of active attacks: address-table churn, changed address mappings, rogue DHCP offers, root-bridge changes. Switch port mirroring (SPAN) is the defender's own legitimate copy of traffic, so a mirror session nobody requested belongs on the audit list.

Eight attack classes, the weakness each needs, and the paired control

Module 8 attack classes by effect, weakness, defender's view and first control
Attack classEffectWeakness it relies onWhat a defender observesFirst-line control
MAC floodingThe switch's address table fills, and it floods frames out every port like a hubA finite address table that learns any source addressA burst of new hardware addresses on one port, table at capacityPort security (cap addresses per port)
DHCP starvationThe lease pool runs dry, and new clients get no addressDHCP serves any requesterPool exhaustion, many client identifiers behind one portPort security, DHCP snooping
Rogue DHCP serverClients receive a bogus gateway or DNS server, putting a third party in the pathClients accept the first offer they getOffers from a server nobody registered, clients with unexpected gatewaysDHCP snooping
ARP poisoningHosts map a trusted IP (often the gateway) to the wrong hardware address, putting a third party in the pathARP is stateless and unauthenticatedA critical IP's hardware address changes in host tables, duplicate-address alertsDynamic ARP Inspection, static entries for critical hosts
MAC spoofingA device borrows another device's hardware address to inherit its accessAccess decisions made on hardware address aloneA known address showing a device profile that does not match the asset record802.1X port authentication instead of MAC filtering
DNS poisoningA correct name resolves to an attacker-chosen addressResolvers that accept unauthenticated answersAnswers that differ from the authoritative zone, users meeting certificate warningsDNSSEC validation, hardened resolvers
VLAN hoppingFrames reach a VLAN the port was never assigned to (switch spoofing or double tagging)Auto-negotiated trunking, a native VLAN shared with usersTrunk negotiation appearing on access portsDisable trunk negotiation on access ports, unused native VLAN
STP manipulationA rogue device wins the root-bridge election and traffic reroutes through itSwitches accept bridge protocol messages on any portUnexpected root-bridge change, topology-change noticesBPDU guard on access ports, root guard

The last column is the first-line answer; defense in depth layers other controls on top. Each feature gets its own walkthrough in Layer 2 attacks and the switch feature that blocks each.

Reading a sniffing scenario in four passes

  1. Find the layer from the nouns

    Address table or ports: MAC attacks. IP-to-hardware mapping: ARP. Leases or address pool: DHCP. A right name landing on a wrong site: DNS. Trunks and tags: VLAN hopping. Root bridge: STP.
  2. Name the effect

    Decide whether the scenario describes exposure (traffic visible), redirection (a third party in the path), denial (exhaustion or outage) or impersonation. The attack class follows from the effect more reliably than from any tool named in the scenario.
  3. Pair the control

    Use the table row. Neighboring rows hold real controls that solve a different problem: DHCP snooping, for one, helps ARP defense only by feeding its bindings to Dynamic ARP Inspection.
  4. Separate detection from prevention

    A question about what reveals an attack wants a monitoring signal: an alert on mapping changes, a port-security violation log, promiscuous-mode detection. One about what stops it wants a preventive control, usually a switch feature. Keep the two lists apart in your notes.

Call the attack, name the control

These targets mix definitions, symptoms and controls from Module 8. The note under every option explains why it holds or fails.

Answered 0/17Hits 0

T-01

A junior administrator argues that enforcing TLS 1.3 across all corporate workstations eliminates the need for switch-level ARP controls. Why is this security architecture proposal fundamentally flawed?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ANetwork devices forwarding frames do not decrypt TLS; this claim is false and does not explain the flaw.
  2. BARP is a Layer 2 protocol carried directly in Ethernet frames, not in UDP, so this reasoning is incorrect.
  3. CCorrect: TLS protects payload confidentiality, but ARP poisoning can still redirect or drop traffic at Layer 2, so switch controls like Dynamic ARP Inspection remain necessary.
  4. DTLS 1.3 handshakes are protected against tampering by design, so simple modification of initial packets is not the core problem.
T-02

After enabling DHCP snooping on distribution switches, legitimate network clients immediately fail to obtain IP addresses. Which configuration oversight most likely caused this sudden network outage?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AGratuitous ARP is unrelated to DHCP snooping and would not stop clients from getting addresses.
  2. BDHCP relay does not require encryption keys, so missing keys cannot explain the failure.
  3. CRate limits apply to untrusted access ports and would not normally be placed on core router interfaces in a way that blocks all clients.
  4. DCorrect: DHCP snooping treats every port as untrusted by default, so offers from the server are dropped unless its uplink is marked trusted.
T-03

During a scheduled maintenance window, gratuitous ARPs for a virtual IP move between two MAC addresses. Four hours later, repeated unsolicited ARP replies claim multiple unrelated host IPs from a single MAC on an access port. Which observation warrants immediate escalation?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AGratuitous ARPs moving a virtual IP during planned failover are expected redundancy behavior, so treating every such change as an attack produces false alarms.
  2. BGratuitous ARP is a normal mechanism for failover and address announcements, so escalating both events equally ignores the context that separates benign from malicious.
  3. CCorrect: one MAC on an access port claiming many unrelated IP addresses through unsolicited replies, outside any change window, is a strong ARP poisoning indicator.
  4. DThese ARPs match a scheduled virtual IP failover between two devices, which explains them and makes them the lower-priority observation.
T-04

Which cybersecurity practice involves passively monitoring network traffic to collect data about protocols, IP addresses, and more?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: network sniffing passively captures traffic to analyze protocols, addresses and contents, for troubleshooting or by attackers seeking plaintext data.
  2. BPenetration testing actively attempts to exploit weaknesses rather than just passively observing traffic.
  3. CSpear phishing, often misspelled as spearfishing, sends targeted deceptive emails rather than monitoring network traffic.
  4. DFirewall configuration defines rules for allowing or blocking traffic and does not collect traffic data.
T-05

A security dashboard alerts on frequent MAC address changes originating from a mobile BYOD segment. There are no signs of CAM table exhaustion. What is the most plausible explanation?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ARouters rewrite Layer 2 headers at each hop as normal behavior, which would not appear as constant MAC changes within one segment.
  2. BMalware that changes endpoint MAC addresses is possible but unlikely as the explanation for widespread changes on a mobile segment.
  3. CPersistent MAC spoofing is possible, but with no CAM flooding and only mobile devices involved, a benign explanation is far more plausible.
  4. DCorrect: modern iOS and Android devices use private, randomized MAC addresses per network and may rotate them, which looks like frequent changes.
T-06

During incident response, an analyst configured `host 10.0.0.5 and port 80` before starting Wireshark. Why is critical evidence of an FTP brute-force attack missing from the subsequent analysis?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThe expression host and port is capture filter syntax applied before the capture, not a malformed display filter.
  2. BBPF capture filters select packets by criteria; they do not automatically truncate payloads by MTU.
  3. CCorrect: a capture filter limited to port 80 drops all other traffic at capture time, so FTP sessions on port 21 were never recorded.
  4. DNothing in the scenario points to mirroring limited to management traffic; the configured filter alone explains the missing evidence.
T-07

You are performing a security audit and need to identify communication channels that expose sensitive data in plaintext. Which of the following network protocols ensures data is always encrypted and is thus NOT susceptible to sniffing?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASMTP transmits email in plaintext unless STARTTLS or SMTPS is used, so it can be sniffed.
  2. BFTP sends credentials and data in cleartext, making it a classic sniffing target, which is why SFTP or FTPS replace it.
  3. CCorrect: SSH encrypts the entire session, including authentication, so passively sniffed traffic does not reveal credentials or commands.
  4. DTelnet sends everything, including passwords, in plaintext, and SSH was designed to replace it.
T-08

What attack targets the Border Gateway Protocol to redirect internet traffic through an attacker-controlled path?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AOSPF spoofing targets an internal routing protocol within one organization, not internet routing between autonomous systems.
  2. BCorrect: BGP hijacking announces IP prefixes an attacker does not own so internet traffic is routed through them; RPKI and route filtering help prevent it.
  3. CRIP manipulation targets a legacy interior routing protocol within small networks, not BGP.
  4. DRoute poisoning is a legitimate distance-vector loop prevention mechanism that advertises failed routes as unreachable, not a BGP attack.
T-09

What technique exploits the lack of security in Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS) to steal authentication credentials?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: when DNS fails, Windows falls back to LLMNR and NBT-NS broadcasts, which an attacker can answer to capture hashes; disabling both protocols prevents this.
  2. BSMB relay forwards captured authentication to another server and often follows LLMNR poisoning, but it is a separate technique.
  3. CDNS poisoning corrupts DNS resolver caches or responses, not local LLMNR or NetBIOS name broadcasts.
  4. DKerberos ticket forging, such as golden tickets, requires compromised key material and does not exploit name resolution fallback.
T-10

An incident-response team must investigate suspected session interception on a switched subnet. Corporate policy mandates minimal collection of unrelated user traffic for privacy compliance. Which combination of capture method and filter achieves optimal evidence preservation while reducing legal exposure?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA promiscuous NIC on a switched network only sees broadcast and the investigator's own traffic, and it captures unrelated data without filtering.
  2. BCapturing on the victim's endpoint risks altering evidence and still records all that host's traffic without a narrowing filter.
  3. CCorrect: a TAP gives a faithful copy of segment traffic, and a capture-time BPF filter on the victim's IP and suspect MAC limits collection to relevant packets.
  4. DA display filter only hides packets after capture, so the full trunk capture still stores unrelated user traffic, breaching the minimal collection policy.
T-11

What is Tcpdump used for?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ADNS queries are made with tools such as dig or nslookup rather than tcpdump.
  2. BCorrect: tcpdump is a command-line packet capture and analysis tool that uses BPF filters to record network traffic.
  3. CPort scanning is done with tools such as Nmap; tcpdump only listens and does not probe hosts.
  4. DFirewall monitoring relies on logs and management tools, whereas tcpdump captures packets on any interface.
T-12

As an ethical hacker, you are tasked with analyzing network traffic to identify vulnerabilities. Which of the following tools provides a GUI interface for network protocol analysis that enhances ease of use for beginners?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: Wireshark is the standard graphical protocol analyzer, with color coding, dissectors and stream views that make captures approachable for beginners.
  2. BNetworkScan GUI is not a recognized protocol analysis tool in common security toolkits.
  3. CProxifier routes application traffic through proxy servers; it does not dissect or analyze network protocols.
  4. DPacketViz is not an established protocol analyzer; Wireshark is the widely used graphical option.
T-13

Switch logs show MAC address AA:BB:CC:DD:EE:01 alternating between ports Gi0/5 and Gi0/12 every 30 seconds. A separate wireless segment shows multiple clients using randomized MACs but maintaining stable port associations. Which event warrants investigation and what additional data is needed?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ARandomized MACs with stable associations are expected privacy behavior on modern devices, and certificate checks would not explain the wired anomaly.
  2. BTreating both events as equal spoofing indicators ignores the benign randomization pattern, and capturing all ports is heavy and unfocused.
  3. CCorrect: one MAC alternating between two wired ports suggests spoofing, a loop or a misconfigured link, so checking physical locations, CDP/LLDP neighbors and traffic narrows it down.
  4. DMAC randomization is normal, but a fixed address flapping between two wired ports is not, so dismissing both events misses a real anomaly.
T-14

Which attack involves exploiting the trust a server has in a client's IP address for authentication?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: IP spoofing forges a trusted source address to abuse host-based trust, which is why address-based authentication is considered weak.
  2. BDNS hijacking redirects name resolution to attacker-controlled servers rather than impersonating a trusted client IP address.
  3. CSession fixation forces a victim to use a session identifier the attacker knows, which targets web sessions rather than IP-based trust.
  4. DCookie manipulation alters browser cookies to change application state or identity, not the source IP address the server trusts.
T-15

Which technique modifies network traffic in transit to inject malicious content or alter legitimate communications?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: packet injection inserts forged or altered packets into a communication stream, typically from a man-in-the-middle position, to change what endpoints receive.
  2. BTraffic analysis studies patterns such as timing, volume and endpoints without altering the traffic itself.
  3. CPacket sniffing passively captures traffic for inspection and does not modify what is sent.
  4. DProtocol fuzzing sends malformed input to software to find bugs, rather than altering live communications between parties.
T-16

Which of the following components MUST be manipulated during a DNS spoofing attack?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThe network interface card simply sends and receives frames and is not what DNS spoofing alters.
  2. BFirewalls may fail to stop spoofed responses, but DNS spoofing does not require changing firewall settings.
  3. CRouters forward packets between networks; DNS spoofing targets name resolution data rather than routing tables.
  4. DCorrect: DNS spoofing places forged name-to-address records into a resolver's cache, so users are sent to the wrong IP; DNSSEC and randomized query IDs help prevent it.
T-17

What is a SIMPLE method to isolate network traffic pertaining to a particular communication between two devices using Wireshark?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: Follow TCP Stream applies a filter for that conversation automatically and shows the reassembled exchange between the two endpoints.
  2. BThe Statistics menu summarizes conversations and endpoints, but it is less direct than following the stream from a selected packet.
  3. CDouble-clicking opens one packet's details but does not isolate the rest of the conversation.
  4. DManual filters work, but Wireshark can build the conversation filter automatically, so it is not the only way.

Sniffing, asked and answered

Why does a switched network not stop sniffing by itself?

A switch limits which port receives a frame, but it learns addresses and mappings from traffic it never authenticates. The active attacks in the table abuse that trust, which is why prevention sits in features that check what the switch learns: port security, DHCP snooping and Dynamic ARP Inspection.

What can I safely skip?

Header bit layouts beyond the basics, tool option lists and vendor-specific feature labels. The blueprint lists concepts, attacks, tools, countermeasures and detection with no vendor syntax (CEH blueprint v5.0, as of Oct 11, 2026), so the generic name of each control is enough.

Do VLAN hopping and STP attacks belong to sniffing?

Yes. The CEH v13 course outline lists both under Module 8 (as of Oct 11, 2026). Both end the same way as the other rows in the table: frames in front of a device that should never see them.

How does sniffing connect to social engineering?

Through redirection. DNS poisoning and pharming both send a user who typed the right name to the wrong site, and social engineering attacks on people often need that redirect to look convincing. On the exam, the network mechanism belongs to Module 8; the deception of the person belongs to Module 9.

Sources