Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 312-50 Exam - Topic 11 Question 103 Discussion

In a large organization, a network security analyst discovered a series of packet captures that seem unusual.The network operates on a switched Ethernet environment. The security team suspects that an attacker mightbe using a sniffer tool. Which technique could the attacker be using to successfully carry out this attack,considering the switched nature of the network?
B) The attacker might be implementing MAC flooding to overwhelm the switch's memory
A) The attacker might be compromising physical security to plug into the network directly
C) The attacker is probably using a Trojan horse with in-built sniffing capability
D) The attacker might be using passive sniffing, as it provides significant stealth advantages Explanation: A sniffer tool is a software or hardware device that can capture and analyze network traffic. In a switched Ethernet environment, where each port on a switch is connected to a single device, a sniffer tool can only see the traffic that is destined for or originated from the device it is attached to. However, an attacker can use various techniques to overcome this limitation and sniff the traffic of other devices on the same network. One of these techniques is MAC flooding, which exploits the finite memory of the switch's MAC address table. The attacker sends a large number of frames with different source MAC addresses to the switch, which fills up the MAC address table and causes the switch to enter a fail-open mode, where it broadcasts all incoming frames to all ports, regardless of the destination MAC address. This way, the attacker can see all the traffic on the network and capture it with a sniffer tool. The other options are less likely or less effective techniques for sniffing a switched Ethernet network. Compromising physical security to plug into the network directly may allow the attacker to sniff the traffic of the device they are connected to, but not the traffic of other devices on the network. Using a Trojan horse with in-built sniffing capability may allow the attacker to sniff the traffic of the infected device, but not the traffic of other devices on the network, unless the Trojan horse also performs MAC flooding or other techniques to bypass the switch. Using passive sniffing, which involves listening to the network traffic without sending any packets, may provide significant stealth advantages, but it does not help the attacker to see the traffic of other devices on the network, unless the switch is already in fail-open mode or the attacker uses other techniques to induce it. Reference: Sniffing: A Beginners Guide In 4 Important Points How can I run a packet sniffer on a Router or Switch Detection of Sniffers in an Ethernet Network

Eccouncil 312-50 Exam - Topic 11 Question 103 Discussion

Actual exam question for Eccouncil's 312-50 exam
Question #: 103
Topic #: 11
[All 312-50 Questions]

In a large organization, a network security analyst discovered a series of packet captures that seem unusual.

The network operates on a switched Ethernet environment. The security team suspects that an attacker might

be using a sniffer tool. Which technique could the attacker be using to successfully carry out this attack,

considering the switched nature of the network?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Jerlene
8 months ago
Wait, can a Trojan really sniff traffic like that? Sounds fishy.
upvoted 0 times
...
Yaeko
8 months ago
Totally agree, MAC flooding is the way to go!
upvoted 0 times
...
Billy
8 months ago
Passive sniffing seems too risky, right?
upvoted 0 times
...
Paz
8 months ago
I think compromising physical security is more likely.
upvoted 0 times
...
Clarence
8 months ago
MAC flooding is definitely a common tactic!
upvoted 0 times
...
Sherrell
9 months ago
I feel like using a Trojan horse is a bit of a stretch for this scenario. It might only capture traffic from the infected device, not the whole network.
upvoted 0 times
...
Eileen
9 months ago
I practiced a similar question last week, and I think passive sniffing is tricky. It might not work unless the switch is already in fail-open mode.
upvoted 0 times
...
Daniel
9 months ago
I'm not entirely sure, but I think compromising physical security could also be a way to sniff traffic. It just seems less effective for capturing everything.
upvoted 0 times
...
Mozell
9 months ago
I remember studying about MAC flooding in class. It seems like the most likely technique here since it can make the switch broadcast all traffic.
upvoted 0 times
...
Dorothy
9 months ago
Okay, I think I've got it. MAC flooding is the key technique the attacker would likely use to sniff traffic on a switched network. I'll make sure to explain that clearly in my answer.
upvoted 0 times
...
Georgiann
9 months ago
I'm a bit confused about the different options. I'll need to make sure I understand the differences between physical access, Trojans, and passive sniffing before deciding on the best answer.
upvoted 0 times
...
Keena
9 months ago
Hmm, MAC flooding sounds like the most likely attack technique here. I'll make sure to review how that works and the implications for a switched network.
upvoted 0 times
...
Rosendo
9 months ago
This seems like a tricky one. I'll need to think carefully about the switched network environment and how an attacker could bypass the security measures.
upvoted 0 times
...

Save Cancel