CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A tester on an internal network engagement floods a switch segment with forged DHCPDISCOVER packets to exhaust the legitimate DHCP server's address pool, then stands up an attacker-controlled DHCP server that assigns clients a malicious default gateway, enabling traffic interception. What is this attack called?

  1. ADNS cache poisoning
  2. BARP spoofing
  3. CVLAN hopping
  4. DDHCP starvation attack
Show answer & explanation

Correct answer: D. DHCP starvation attack

Exhausting the DHCP pool with forged requests and then serving malicious configuration via a rogue DHCP server is a DHCP starvation attack, often paired with rogue DHCP setup to perform man-in-the-middle attacks. ARP spoofing manipulates ARP caches directly, VLAN hopping bypasses VLAN segmentation, and DNS cache poisoning corrupts DNS resolver records.

Why the other options are wrong

  • A. DNS cache poisoning corrupts DNS resolution records, not DHCP address leasing.
  • B. ARP spoofing manipulates ARP tables to redirect traffic, not DHCP pool exhaustion.
  • C. VLAN hopping uses trunking or double-tagging tricks to cross VLAN boundaries, unrelated to DHCP.

DHCP Starvation Attack

An attack where an adversary floods a network with forged DHCP request packets to exhaust the available IP address pool, often followed by deploying a rogue DHCP server to control client network configuration.

  • Exhausts legitimate DHCP server's lease pool with spoofed MAC addresses
  • Often paired with a rogue DHCP server for MITM attacks
  • Tools like Yersinia or dhcpstarv can automate the flood

Memory trick: Starve the pool, then serve poisoned addresses

More Attacks and Exploits questions