ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityMedium
A security analyst is investigating a series of network performance degradation incidents. Analysis reveals that the network is being flooded with ARP requests, causing switches to exhaust their CAM table entries and broadcast traffic excessively. This leads to legitimate traffic being dropped or delayed. Which of the following network attacks is MOST likely occurring?
- AMAC Flooding
- BDNS Amplification
- CSYN Flood
- DARP Poisoning
Show answer & explanationAnswer & explanation
Correct answer: A. MAC Flooding
MAC flooding attacks overwhelm a switch's Content Addressable Memory (CAM) table with fake MAC address-port mappings. When the CAM table is full, the switch enters 'fail-open' mode and acts like a hub, broadcasting all incoming traffic to all ports, leading to performance degradation and potential eavesdropping.
Why the other options are wrong
- B. DNS Amplification is a type of DDoS attack that uses open DNS resolvers to amplify attack traffic, targeting network bandwidth, not switch CAM tables.
- C. SYN Flood is a DoS attack targeting TCP servers, exhausting connection tables, not switch CAM tables.
- D. ARP Poisoning manipulates ARP caches to redirect traffic, not directly flood CAM tables with random MACs.
MAC Flooding
A network attack that overwhelms a switch's Content Addressable Memory (CAM) table by sending a large number of frames with different source MAC addresses. This forces the switch to broadcast all incoming traffic to all ports, effectively turning it into a hub.
- Targets Layer 2 switches.
- Overwhelms the switch's CAM table.
- Causes the switch to enter fail-open mode, broadcasting all traffic.
- Can lead to network performance degradation and traffic interception.
Memory trick: MACs And ARPs Poison Networks Easily.