Courseiva
Networking and Protocols →mediumMultiple Choice

GSEC Networking and Protocols Practice Question

A security analyst is investigating a suspected man-in-the-middle attack on a switched corporate network. The analyst reviews switch logs and notices that a single physical port has learned an unusually large number of distinct MAC addresses within a short period. The analyst wants to determine which attack technique this behavior most directly indicates and what impact it produces on the switch's forwarding behavior. Which statement best describes this scenario?

⚠ Common exam trap

The trap here is conflating any Layer 2 man-in-the-middle technique with the specific CAM table exhaustion signature that only MAC flooding produces.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MAC flooding, where the attacker fills the content-addressable memory table so the switch floods frames out all ports.

A switch port learning an excessive number of distinct MAC addresses indicates MAC flooding, in which spoofed source addresses exhaust the CAM table. Once the table overflows, the switch floods unknown unicast frames to all ports, enabling the attacker to capture traffic. This differs from ARP spoofing and STP attacks, whose signatures involve forged mappings or BPDUs rather than a MAC learning spike.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VLAN hopping, where the attacker injects double-tagged frames to reach a different VLAN.

    Why it's wrong here

    VLAN hopping involves manipulating 802.1Q tags, such as double tagging or switch spoofing, to cross VLAN boundaries. It does not inherently cause a switch port to learn many distinct MAC addresses. While both are Layer 2 attacks, the signature described, a flood of source MACs on one port, points elsewhere. Confusing the two techniques would send the analyst toward the wrong mitigation, such as pruning VLANs rather than port protection.

  • ✓

    MAC flooding, where the attacker fills the content-addressable memory table so the switch floods frames out all ports.

    Why this is correct

    MAC flooding sends frames with many spoofed source MAC addresses, exhausting the switch's CAM table. Once the table is full, the switch cannot map destinations to ports and falls back to flooding unknown unicast frames out every port, allowing the attacker to capture traffic intended for other hosts. The log pattern of many MACs learned on one port is the direct signature of this technique.

  • ✗

    ARP spoofing, where the attacker sends forged ARP replies to associate their MAC with a victim's IP address.

    Why it's wrong here

    ARP spoofing poisons hosts' ARP caches so traffic is sent to the attacker's MAC. It typically involves a small number of MAC-to-IP mappings, not a flood of distinct source MAC addresses on a single port. The switch log signature differs: ARP spoofing produces many ARP replies but few unique source MACs, whereas the scenario shows an abnormal volume of learned addresses.

  • ✗

    STP root bridge takeover, where the attacker sends superior BPDUs to become the root of the spanning tree.

    Why it's wrong here

    An STP root bridge takeover involves sending crafted Bridge Protocol Data Units with a lower bridge ID to win the root election and reposition the topology so traffic traverses the attacker. It does not cause a port to learn a large number of MAC addresses. The described CAM table growth is unrelated to spanning-tree topology manipulation and would not be detected through MAC learning logs.

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.