
EC-CouncilCertified Ethical Hacker
Domain 4Objective 1
Sniffing and ARP Poisoning CEH Practice Questions (Page 6)
Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
5concepts
Questions 26–30
- 26
A penetration tester is performing an internal assessment and needs to capture credentials transmitted over HTTP from a specific user's workstation. The tester has physical access to the network but not to the workstation. Which approach would be most effective?
Select an answer first - 27
A network administrator is setting up a monitoring solution to capture traffic on a switched network without disrupting operations. The goal is to analyze traffic between two servers. Which method should the administrator use?
Select an answer first - 28
A security analyst is testing the network for ARP poisoning vulnerabilities. The analyst wants to intercept traffic between a client and the gateway without disrupting the client's connectivity. Which tool and technique combination would achieve this?
Select an answer first - 29
A security analyst is reviewing packet captures and notices that the ARP cache on a server has been modified to point to an unknown MAC address. The analyst also sees a high volume of ARP replies from a single IP address. Which countermeasure would be most effective in preventing this type of attack in the future?
Select an answer first - 30
What is the primary goal of a MAC flooding attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.