🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 59 minutes remaining!

Certified Ethical Hacker (CEH) Practice Question

During an internal security assessment you are allowed to run only active tests that will not disrupt production. To identify any workstations on a switched Ethernet segment that have their network cards set to promiscuous (sniffer) mode, you transmit a single Ethernet frame carrying an ARP request that lists the suspected host's IP address but sets the frame's destination MAC to 00:11:22:33:44:55-an address that does not belong to any device on the segment and is not the broadcast address. Which observation would confirm that the workstation is operating in promiscuous mode?

  • Repeated 802.1X EAP authentication failures are logged on the switch port connected to the workstation.

  • The workstation ignores the request but later sends a gratuitous ARP advertising its MAC for the same IP address.

  • The switch's CAM table briefly overflows and the uplink port shows a spike in traffic from multiple VLANs.

  • The workstation replies with a valid ARP response even though the request's Layer-2 destination MAC does not match its own or the broadcast address.

Certified Ethical Hacker (CEH)
Network and Perimeter Hacking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot