Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 4Objective 1

Sniffing and ARP Poisoning CEH Practice Questions (Page 3)

Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
5concepts

Questions 11–15

  1. 11expert · hard

    A penetration tester is on a switched network and needs to intercept and modify traffic between a client and a server for a red-team exercise. The tester has administrative access to a workstation on the same subnet. The client and server are both on the same VLAN. The tester wants to avoid disrupting the network and wants to ensure that the client can still reach the server during the test. Which approach BEST meets these requirements?

    Select an answer first
  2. 12expert · hard

    A security analyst is investigating a network where users report slow internet and intermittent connectivity. The analyst captures traffic and sees a large number of ARP replies from a single MAC address claiming to be the gateway. The switch does not have DHCP snooping or DAI enabled. Which action would be most effective to stop the attack?

    Select an answer first
  3. 13application · medium

    A network analyst is using Wireshark to capture traffic on a network segment. The analyst notices that the capture contains many packets with the source MAC address of the default gateway but the source IP address of a different host. What does this indicate?

    Select an answer first
  4. 14expert · hard

    A security analyst is investigating a suspected ARP poisoning attack. The analyst captures traffic and sees a large number of ARP replies from a single MAC address claiming to be the default gateway. The analyst also notices that the gateway's real MAC address is different. Which action would BEST confirm the attack and identify the attacking host?

    Select an answer first
  5. 15application · medium

    A network administrator is setting up a monitoring solution to detect unauthorized sniffing on the corporate network. The administrator wants to identify if any host is running its network interface in promiscuous mode. Which technique is MOST effective for this purpose?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.