CompTIA Network+ (N10-009)Network SecurityMedium
A penetration tester connects a laptop to an access port and successfully sends traffic to a VLAN it should not have access to by crafting frames with two 802.1Q tags. Which attack technique was used?
- AMAC flooding
- BARP poisoning
- CDHCP starvation
- DDouble tagging VLAN hopping
Show answer & explanationAnswer & explanation
Correct answer: D. Double tagging VLAN hopping
Double tagging is a VLAN hopping technique where an attacker adds two 802.1Q tags; the first switch strips the outer (native VLAN) tag, and the inner tag lets the frame reach a VLAN the attacker shouldn't access.
Why the other options are wrong
- A. MAC flooding overwhelms a switch's CAM table to force it into hub mode, not tag manipulation.
- B. ARP poisoning corrupts ARP caches to redirect traffic, unrelated to VLAN tags.
- C. DHCP starvation exhausts the DHCP pool by requesting all available leases.
VLAN Hopping (Double Tagging)
An attack where a frame is crafted with two VLAN tags so it can traverse from the native VLAN into a restricted VLAN by exploiting how trunk switches strip only the outer tag.
- Requires attacker's port to be on the native VLAN of the trunk
- Only works one-way (attacker to victim VLAN)
- Mitigated by not using VLAN 1 as native VLAN and explicitly tagging native VLAN traffic
Memory trick: Two tags, one jump — double tagging hops the fence.