CEH Practice Question: Malware, Social Engineering and Network Attacks
A network administrator notices that the switch's CAM table is full, causing the switch to flood all incoming traffic out of all ports. Which attack is MOST likely occurring?
⚠ Common exam trap
In EC-CEH exams, MAC flooding (which fills the CAM table) is often confused with ARP poisoning (which poisons the ARP cache). Both can lead to traffic interception, but the cause differs: MAC flooding exploits the switch's learning mechanism, while ARP poisoning manipulates the host's ARP table.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MAC flooding
MAC flooding attacks exploit the limited size of a switch's Content Addressable Memory (CAM) table by sending thousands of frames with unique, random source MAC addresses. Once the CAM table is full, the switch enters a fail-open state and begins flooding all incoming frames out every port, effectively turning it into a hub and allowing the attacker to sniff traffic. This directly matches the scenario where a full CAM table causes flooding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ARP poisoning
Why it's wrong here
ARP poisoning corrupts the ARP cache to redirect traffic between hosts; it does not populate the CAM table with fabricated source MAC addresses. CAM table overflow requires flooding frames with many spoofed source MACs, exhausting the fixed-size forwarding table so the switch floods all ports. ARP poisoning is used for man-in-the-middle interception instead.
- ✗
DHCP starvation
Why it's wrong here
DHCP starvation exhausts a DHCP server's lease pool by requesting addresses with fabricated client MAC addresses, denying legitimate clients configuration; the switch's CAM table is not the target. CAM table overflow requires flooding frames with many spoofed source MACs to exhaust the forwarding table. DHCP starvation would fit a stem about clients failing to obtain leases.
- ✗
DNS spoofing
Why it's wrong here
DNS spoofing forges name-resolution responses to redirect clients to malicious IP addresses; it never writes entries into the switch's CAM table. CAM table overflow needs a flood of frames bearing spoofed source MAC addresses, exhausting the forwarding table. DNS spoofing would be correct if the stem described falsified DNS replies.
- ✓
MAC flooding
Why this is correct
MAC flooding overwhelms the switch's CAM table with forged source MAC addresses, exhausting its capacity. Once full, the switch cannot map addresses to ports and floods all incoming frames out of every port, satisfying the described symptom of indiscriminate flooding.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.