CompTIA Network+ (N10-009)Network SecurityEasy
A technician notices that a switch has begun flooding unicast frames out every port instead of forwarding them only to the correct destination port. An analysis shows the switch's MAC address table is completely full of thousands of random, spoofed source MAC addresses received on a single port. Which attack is most likely occurring?
- ARogue DHCP server
- BARP spoofing
- CVLAN hopping
- DMAC flooding
Show answer & explanationAnswer & explanation
Correct answer: D. MAC flooding
MAC flooding overwhelms the switch's content-addressable memory (CAM) table with bogus MAC addresses, causing it to fail open and broadcast traffic out all ports so the attacker can sniff data meant for other hosts. ARP spoofing, VLAN hopping, and rogue DHCP servers target different mechanisms and would not cause CAM table exhaustion.
Why the other options are wrong
- A. A rogue DHCP server hands out bad IP configurations, it doesn't fill the MAC table.
- B. ARP spoofing manipulates ARP caches, not the switch's MAC table.
- C. VLAN hopping bypasses VLAN boundaries via tagging, unrelated to CAM table size.
MAC Flooding
An attack that overwhelms a switch's finite CAM (MAC address) table with fake entries, causing the switch to broadcast traffic to all ports like a hub, enabling sniffing.
- Exploits limited size of the switch's CAM table
- Switch fails open and floods frames out all ports
- Mitigated with port security limiting MACs per port
Memory trick: Flood the table, flood the traffic.