Courseiva

What Is a MAC Flooding Attack?

A network administrator receives an alert that the switch's CAM table is full, causing the switch to flood frames out all ports. Which attack has likely occurred?

Quick Answer

The correct answer is a MAC flooding attack. This is because a MAC flooding attack overwhelms the switch’s Content Addressable Memory (CAM) table with thousands of fake source MAC addresses, causing the table to reach its capacity. Once full, the switch can no longer store legitimate MAC-to-port mappings and defaults to flooding all incoming frames out every port, effectively operating like a hub. This behavior allows an attacker connected to any port to capture traffic not intended for them, a technique known as sniffing. On the Certified Ethical Hacker CEH exam, this question tests your understanding of Layer 2 attacks and switch security weaknesses. A common trap is confusing MAC flooding with ARP poisoning; remember that MAC flooding targets the CAM table, while ARP poisoning targets the ARP cache. For a quick memory tip, think “Flood the CAM, act like a hub.”

⚠ Common exam trap

In the EC-CEH exam, MAC flooding is often contrasted with ARP poisoning; the trap here is that candidates confuse the layer-2 CAM table overflow with layer-3 ARP cache manipulation, but ARP poisoning does not cause the switch to flood frames out all ports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MAC flooding

MAC flooding (Option C) is the correct answer because it directly exploits the limited size of a switch's Content Addressable Memory (CAM) table. By sending a high volume of frames with unique, spoofed source MAC addresses, the attacker fills the CAM table, forcing the switch to fail open and flood all incoming frames out every port, effectively turning it into a hub. This allows the attacker to capture traffic that was not originally destined for their port.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS spoofing

    Why it's wrong here

    DNS spoofing forges DNS responses to redirect name resolution; it never writes entries into the switch's CAM table, so no overflow occurs. It is tempting because DNS spoofing also redirects victim traffic, which suits poisoning resolver caches rather than flooding a switch's MAC address table.

  • ✗

    ARP poisoning

    Why it's wrong here

    ARP poisoning corrupts IP-to-MAC mappings in hosts' ARP caches; it does not populate the CAM table with fabricated source MACs, so the table does not fill. It is tempting because ARP poisoning also enables traffic interception on a switched segment, which suits man-in-the-middle scenarios rather than CAM overflow.

  • ✓

    MAC flooding

    Why this is correct

    MAC flooding overwhelms the switch's CAM table by sending numerous frames with spoofed source MAC addresses, exhausting its finite entry capacity. Once full, the switch cannot map addresses to ports and falls back to hub-like behaviour, flooding every frame out all ports — precisely the alert described in the stem.

  • ✗

    SYN flood

    Why it's wrong here

    A SYN flood exhausts the TCP connection backlog or state table, not the CAM table, so the switch does not flood frames. It is tempting because SYN floods also cause denial of service on a switched network, which suits exhausting server resources rather than overflowing Layer 2 MAC address tables.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on CEH

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security administrator notices that the network switch is broadcasting traffic to all ports as if it were a hub. The switch logs show a sudden flood of packets with random MAC addresses. Which attack is MOST likely occurring?

easy
  • A.SYN flood
  • ✓ B.MAC flooding
  • C.ARP poisoning
  • D.DNS amplification

Why B: B is correct because MAC flooding attacks exploit the limited size of a switch's Content Addressable Memory (CAM) table. By sending a flood of packets with random source MAC addresses, the attacker fills the CAM table, forcing the switch to fail-open into hub mode (broadcasting all traffic to all ports) so that the attacker can capture frames not originally destined for their port.

Variation 2. A network administrator notices that the switch's CAM table is full, causing the switch to flood all incoming traffic out of all ports. Which attack is MOST likely occurring?

medium
  • A.ARP poisoning
  • B.DHCP starvation
  • C.DNS spoofing
  • ✓ D.MAC flooding

Why D: MAC flooding attacks exploit the limited size of a switch's Content Addressable Memory (CAM) table by sending thousands of frames with unique, random source MAC addresses. Once the CAM table is full, the switch enters a fail-open state and begins flooding all incoming frames out every port, effectively turning it into a hub and allowing the attacker to sniff traffic. This directly matches the scenario where a full CAM table causes flooding.

Variation 3. During a penetration test, you run the tool 'macof' against a switch. After a few seconds, the switch starts flooding frames out all ports. Which attack have you successfully executed, and what is the primary goal of this technique?

hard
  • ✓ A.MAC flooding; to cause a switch to fail-open and act like a hub for sniffing
  • B.VLAN hopping; to gain access to a different VLAN
  • C.STP manipulation; to create a loop and cause a DoS
  • D.ARP poisoning; to intercept traffic between two hosts

Why A: The 'macof' tool is specifically designed to perform MAC flooding attacks by generating frames with random source MAC addresses. This overwhelms the switch's Content Addressable Memory (CAM) table, causing it to fail-open and flood all incoming frames out every port, effectively making it behave like a hub. This allows the attacker to sniff network traffic that would normally be isolated to specific switch ports.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.