A forensic analyst is investigating a network breach and finds that the attacker used a technique that bypasses Network Access Control (NAC). Which of the following methods is commonly used to evade 802.1X authentication?
Trap 1: VLAN hopping using double tagging
VLAN hopping via double tagging is incorrect for this scenario because the attack exploits an improperly configured trunk port to send frames with two 802.1Q tags, causing the switch to forward them into an unintended VLAN. It targets network segmentation and VLAN isolation, but it operates after an endpoint has already gained admission to the LAN; it does not alter the 802.1X/NAC authentication process itself. Thus it cannot bypass the authentication requirement.
Trap 2: DNS tunneling to exfiltrate data
DNS tunneling is wrong because it is a data exfiltration and command-and-control technique that embeds payloads within DNS queries and responses to slip through egress filtering. While DNS is often allowed through firewalls, the tunnel establishes an encoded or encrypted channel only after the attacker already has a foothold on an authenticated host or network segment. It does not authenticate the attacker to the NAC/802.1X edge and therefore cannot be used to bypass the initial access control.
Trap 3: ARP poisoning to redirect traffic
ARP poisoning is incorrect because it manipulates the IP-to-MAC mapping in the target's ARP cache by sending forged ARP replies, placing the attacker in the middle of the traffic flow on the same broadcast domain. This is a post-admission, Layer 2 man-in-the-middle attack that assumes the attacker is already connected to the authenticated switching port or VLAN; it does not modify the 802.1X or MAC-based authentication state. Consequently, ARP poisoning cannot bypass the NAC's port-based authentication, unlike MAC spoofing.
- A
MAC address spoofing
MAC address spoofing is correct because many 802.1X implementations enable MAC Authentication Bypass (MAB) or trust the device's MAC address as the Layer 2 identity for NAC port control. An attacker who clones an authorized device's MAC address (e.g., using macchanger or NIC driver settings) can trick the authenticator into treating the rogue device as legitimate, thereby gaining authenticated network access without valid user credentials. This directly bypasses the NAC/802.1X authentication decision.
- B
VLAN hopping using double tagging
Why it fails: VLAN hopping via double tagging is incorrect for this scenario because the attack exploits an improperly configured trunk port to send frames with two 802.1Q tags, causing the switch to forward them into an unintended VLAN. It targets network segmentation and VLAN isolation, but it operates after an endpoint has already gained admission to the LAN; it does not alter the 802.1X/NAC authentication process itself. Thus it cannot bypass the authentication requirement.
- C
DNS tunneling to exfiltrate data
Why it fails: DNS tunneling is wrong because it is a data exfiltration and command-and-control technique that embeds payloads within DNS queries and responses to slip through egress filtering. While DNS is often allowed through firewalls, the tunnel establishes an encoded or encrypted channel only after the attacker already has a foothold on an authenticated host or network segment. It does not authenticate the attacker to the NAC/802.1X edge and therefore cannot be used to bypass the initial access control.
- D
ARP poisoning to redirect traffic
Why it fails: ARP poisoning is incorrect because it manipulates the IP-to-MAC mapping in the target's ARP cache by sending forged ARP replies, placing the attacker in the middle of the traffic flow on the same broadcast domain. This is a post-admission, Layer 2 man-in-the-middle attack that assumes the attacker is already connected to the authenticated switching port or VLAN; it does not modify the 802.1X or MAC-based authentication state. Consequently, ARP poisoning cannot bypass the NAC's port-based authentication, unlike MAC spoofing.