A network administrator notices that the switch's CAM table is full, causing the switch to flood all incoming traffic out of all ports. Which attack is MOST likely occurring?
MAC flooding overwhelms the switch's CAM table with forged source MAC addresses, exhausting its capacity. Once full, the switch cannot map addresses to ports and floods all incoming frames out of every port, satisfying the described symptom of indiscriminate flooding.
Why this answer
MAC flooding attacks exploit the limited size of a switch's Content Addressable Memory (CAM) table by sending thousands of frames with unique, random source MAC addresses. Once the CAM table is full, the switch enters a fail-open state and begins flooding all incoming frames out every port, effectively turning it into a hub and allowing the attacker to sniff traffic. This directly matches the scenario where a full CAM table causes flooding.
Exam trap
In EC-CEH exams, MAC flooding (which fills the CAM table) is often confused with ARP poisoning (which poisons the ARP cache). Both can lead to traffic interception, but the cause differs: MAC flooding exploits the switch's learning mechanism, while ARP poisoning manipulates the host's ARP table.
How to eliminate wrong answers
Option A is wrong because ARP poisoning manipulates the IP-to-MAC mappings in a host's ARP cache to redirect traffic, not by filling the switch's CAM table. Option B is wrong because DHCP starvation exhausts the pool of available IP addresses from a DHCP server, causing denial of service for new clients, but it does not fill the switch's CAM table or cause port flooding. Option C is wrong because DNS spoofing corrupts DNS resolution to redirect users to malicious sites, and it has no effect on the switch's MAC address table or flooding behavior.