CompTIA Network+ (N10-009)Network ImplementationHard

A penetration tester crafts an Ethernet frame containing two nested 802.1Q VLAN tags and sends it from a host on the native VLAN of a trunk link. The goal is to have the frame processed on a VLAN the host should not have access to. Which attack is being demonstrated?

  1. ARogue DHCP server attack
  2. BMAC flooding
  3. CARP spoofing
  4. DVLAN hopping via double tagging
Show answer & explanation

Correct answer: D. VLAN hopping via double tagging

Double tagging is a VLAN hopping technique where an attacker on the native VLAN adds two 802.1Q tags; the first switch strips the outer (native VLAN) tag, and the inner tag is then forwarded onto a trunk, causing the frame to appear on a different VLAN than the attacker's actual VLAN, bypassing VLAN isolation.

Why the other options are wrong

  • A. A rogue DHCP server hands out malicious IP configuration information, unrelated to VLAN tagging.
  • B. MAC flooding overwhelms a switch's CAM table to force it into hub-like flooding behavior, not VLAN tag exploitation.
  • C. ARP spoofing manipulates ARP tables to intercept traffic, unrelated to VLAN tag manipulation.

VLAN Hopping (Double Tagging)

An attack where a host on the native VLAN sends frames with two stacked 802.1Q tags; the first switch strips the outer tag, allowing the inner tag to reach a different VLAN than intended, bypassing VLAN segmentation.

  • Only works if attacker is on the native VLAN of a trunk
  • Mitigated by not using VLAN 1 as native VLAN and explicitly tagging native VLAN traffic
  • Traffic is one-way, useful mainly for attacks like DoS or reconnaissance

Memory trick: Two tags, one sneaky hop across the VLAN fence.

More Network Implementation questions