GSEC Networking and Protocols Practice Question
A security analyst is investigating a suspected man-in-the-middle attack on a switched corporate network. The analyst reviews switch logs and notices that a single physical port has learned an unusually large number of distinct MAC addresses within a short period. The analyst wants to determine which attack technique this behavior most directly indicates and what impact it produces on the switch's forwarding behavior. Which statement best describes this scenario?
⚠ Common exam trap
The trap here is conflating any Layer 2 man-in-the-middle technique with the specific CAM table exhaustion signature that only MAC flooding produces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MAC flooding, where the attacker fills the content-addressable memory table so the switch floods frames out all ports.
A switch port learning an excessive number of distinct MAC addresses indicates MAC flooding, in which spoofed source addresses exhaust the CAM table. Once the table overflows, the switch floods unknown unicast frames to all ports, enabling the attacker to capture traffic. This differs from ARP spoofing and STP attacks, whose signatures involve forged mappings or BPDUs rather than a MAC learning spike.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VLAN hopping, where the attacker injects double-tagged frames to reach a different VLAN.
Why it's wrong here
VLAN hopping involves manipulating 802.1Q tags, such as double tagging or switch spoofing, to cross VLAN boundaries. It does not inherently cause a switch port to learn many distinct MAC addresses. While both are Layer 2 attacks, the signature described, a flood of source MACs on one port, points elsewhere. Confusing the two techniques would send the analyst toward the wrong mitigation, such as pruning VLANs rather than port protection.
- ✓
MAC flooding, where the attacker fills the content-addressable memory table so the switch floods frames out all ports.
Why this is correct
MAC flooding sends frames with many spoofed source MAC addresses, exhausting the switch's CAM table. Once the table is full, the switch cannot map destinations to ports and falls back to flooding unknown unicast frames out every port, allowing the attacker to capture traffic intended for other hosts. The log pattern of many MACs learned on one port is the direct signature of this technique.
- ✗
ARP spoofing, where the attacker sends forged ARP replies to associate their MAC with a victim's IP address.
Why it's wrong here
ARP spoofing poisons hosts' ARP caches so traffic is sent to the attacker's MAC. It typically involves a small number of MAC-to-IP mappings, not a flood of distinct source MAC addresses on a single port. The switch log signature differs: ARP spoofing produces many ARP replies but few unique source MACs, whereas the scenario shows an abnormal volume of learned addresses.
- ✗
STP root bridge takeover, where the attacker sends superior BPDUs to become the root of the spanning tree.
Why it's wrong here
An STP root bridge takeover involves sending crafted Bridge Protocol Data Units with a lower bridge ID to win the root election and reposition the topology so traffic traverses the attacker. It does not cause a port to learn a large number of MAC addresses. The described CAM table growth is unrelated to spanning-tree topology manipulation and would not be detected through MAC learning logs.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.