Network Security 14% Lesson 5 of 8

Lesson 4.2.1 — Network-Based Attacks: DoS, VLAN Hopping, MAC Flooding, ARP/DNS Poisoning & On-Path Attacks

Avatar Of Asad IjazAsad Ijaz ·Sep 20, 2026 ·5 min read
63% through domain
Illustration Of A Data Path Being Silently Diverted Toward A Shadowy Off-Path Node

Domain 4.0 | Network Security — 14% of exam

Learning Objectives

By the end of this lesson, you will be able to:

  • Explain DoS and DDoS attacks and how they specifically target availability
  • Describe VLAN hopping and MAC flooding as attacks targeting switch behavior
  • Explain ARP poisoning/spoofing and how it redirects traffic through an attacker
  • Explain DNS poisoning/spoofing and its impact on legitimate name resolution
  • Describe on-path attacks and how earlier attacks in this lesson often enable them

Key Terms – Network-Based Attacks

TermDefinition
DoS (Denial of Service)An attack from a single source that overwhelms a target, denying service to legitimate users
DDoS (Distributed Denial of Service)A DoS attack launched from many distributed sources simultaneously, making it far harder to block
VLAN HoppingAn attack technique allowing traffic to reach a VLAN the attacker shouldn’t have access to
MAC FloodingOverflowing a switch’s MAC address table with bogus entries, causing it to fail open and broadcast traffic like a hub
On-Path AttackAn attack where the attacker intercepts communication between two parties, often enabled by ARP poisoning or a rogue access point

Explanation

From Security Concepts to Active Attacks

Objective 4.1 covered foundational security concepts — the CIA triad, certificates, identity management, and segmentation. This lesson shifts to the active side: specific attack techniques that directly target the network itself, several of which build on each other in ways worth understanding as a connected sequence rather than a disconnected list.

DoS and DDoS: Attacking Availability

A DoS (Denial of Service) attack overwhelms a target — a server, a service, a network link — with traffic or requests from a single source, consuming enough resources that legitimate users can no longer get through. This is a direct, textbook attack on the availability property of the CIA triad — the data itself might remain perfectly confidential and unmodified, but the service becomes unreachable regardless.

A DDoS (Distributed Denial of Service) attack is the same basic idea scaled up dramatically: instead of one source, traffic floods in from many distributed sources simultaneously — often a large network of compromised devices (a botnet) — making the attack both far more powerful and far harder to block, since there’s no single source IP to simply filter out.

Diagram Comparing A Single-Source Dos Attack Against A Distributed Multi-Source Ddos Attack Overwhelming The Same Target
How A Ddos Attack’S Many Distributed Sources Differ From A Single-Source Dos Attack

VLAN Hopping and MAC Flooding: Attacking Switches

Two distinct attack techniques target switch behavior specifically:

VLAN hopping lets an attacker’s traffic reach a VLAN they shouldn’t have legitimate access to, commonly by exploiting a misconfigured trunk port or by crafting frames that manipulate how VLAN trunking and tagging is processed. Properly securing trunk port configuration and avoiding unnecessary default VLAN assignments significantly reduces this risk. MAC flooding targets a switch’s MAC address table (also called its CAM table) directly, overwhelming it with a flood of bogus, fabricated MAC addresses until the table fills up completely. Once that happens, many switches respond by failing open — reverting to broadcasting all traffic out every port, essentially behaving like a hub rather than a switch — which lets an attacker capture traffic on the network segment they’d otherwise never see, since normal switch behavior would only forward traffic to its intended destination port.
Diagram Showing A Frame Crossing Vlan Boundaries Via A Trunk Port Alongside A Switch'S Mac Table Overflowing Into Broadcast Mode
How Vlan Hopping Crosses Segment Boundaries While Mac Flooding Forces A Switch To Broadcast Traffic Indiscriminately

Both attacks share a common theme: exploiting how switches are designed to behave under specific conditions, turning a normal operational mechanism into an opportunity for unauthorized access or traffic interception.

ARP Poisoning and Spoofing

ARP poisoning (also called ARP spoofing) exploits the fact that ARP has no built-in authentication: an attacker sends forged ARP replies claiming that their own MAC address corresponds to another device’s IP address — very often the network’s default gateway. Devices on the local segment update their ARP tables based on these forged replies without verifying them, and traffic that should have gone to the real gateway instead gets sent to the attacker first.

Diagram Showing A Client'S Traffic Redirected Through An Attacker Via A Forged Arp Reply Instead Of Reaching The Legitimate Gateway Directly
How A Forged Arp Reply Redirects Traffic Through The Attacker Instead Of The Legitimate Gateway

Once traffic is flowing through the attacker this way, they can read it, modify it, or simply forward it along to the real destination after inspecting it — the victim typically has no immediate indication anything is wrong, since their connection still appears to work normally.

DNS Poisoning and Spoofing

DNS poisoning (or DNS spoofing) corrupts DNS resolution so that a legitimate domain name resolves to an attacker-controlled IP address instead of the real one. This can happen by corrupting a resolver’s cache with a forged response, or by intercepting and forging a DNS response before the legitimate one arrives. The practical effect is that a user typing in a completely correct, legitimate domain name still ends up connecting to an attacker’s server instead of the real one — the domain name itself was never wrong, but the resolution behind it was compromised.

On-Path Attacks: The Common Destination

An on-path attack (also known as a man-in-the-middle attack) describes any situation where an attacker successfully inserts themselves between two communicating parties, intercepting — and potentially altering — traffic passing between them. This is worth covering last in this lesson specifically because it’s often the actual goal several of the previous techniques are working toward: ARP poisoning is frequently used specifically to position an attacker for an on-path attack, and a rogue access point can achieve a similar result in a wireless context by tricking clients into routing their traffic through the attacker in the first place.

Recognition-Level Verification Concepts

A few patterns are worth recognizing on sight:

  • Traffic arriving from one specific IP address overwhelming a target describes DoS; traffic arriving from many distributed IP addresses simultaneously describes DDoS.
  • Traffic unexpectedly reaching a VLAN it shouldn’t have access to, especially via a trunk port, points to VLAN hopping.
  • A switch suddenly broadcasting traffic to every port instead of only the intended destination points to a MAC flooding attack having succeeded.
  • A device’s ARP table showing the default gateway’s IP mapped to an unfamiliar or incorrect MAC address is a strong sign of ARP poisoning in progress.
  • A correctly typed, legitimate domain name resolving to an unexpected or suspicious IP address points to DNS poisoning, not a typo or user error.

Common Exam Traps

  • DoS and DDoS differ specifically in source distribution, not overall goal. Both aim to deny service; the “distributed” part of DDoS is what makes it dramatically harder to block by simply filtering a single source.
  • VLAN hopping and MAC flooding target different switch mechanisms. VLAN hopping crosses logical segment boundaries; MAC flooding forces the switch into broadcasting behavior — don’t conflate the two just because both target switches.
  • ARP has no built-in authentication, which is exactly why ARP poisoning works at all. Don’t assume ARP replies are inherently trustworthy just because they come from the local network segment.
  • DNS poisoning corrupts resolution, not the domain name itself. The domain the user typed was correct; what they were routed to was not — this distinction matters for correctly diagnosing the actual point of compromise.
  • On-path attacks are often the end goal that other techniques (ARP poisoning, rogue APs) are working toward, not a completely separate, unrelated attack category.

Lesson 4.2.1 Practice Quiz — Network-Based Attacks

17 questions covering DoS/DDoS, VLAN hopping, MAC flooding, ARP poisoning, DNS poisoning, and on-path attacks.

N10-009 · Domain 4.2
Question 1Plain
What is the main difference between DoS and DDoS?
The key difference is source distribution — DDoS uses many distributed sources, making it far harder to block than a single-source DoS attack.
Question 2Plain
What does a successful MAC flooding attack cause a switch to do?
Once the MAC table overflows, many switches fail open and start broadcasting traffic to every port, letting an attacker capture traffic they shouldn't see.
Question 3Plain
What does ARP poisoning exploit?
ARP poisoning works specifically because ARP has no built-in authentication, letting forged replies be accepted without verification.
Question 4Choose Two
Which two statements about DoS and DDoS are correct? (Choose two.)
Both DoS and DDoS directly target availability, and DDoS's distributed sources make it significantly harder to block than a single-source DoS attack.
Question 5Choose Two
Which two statements correctly distinguish VLAN hopping from MAC flooding? (Choose two.)
VLAN hopping crosses logical VLAN boundaries; MAC flooding overflows the MAC table to force broadcast behavior — these are distinct mechanisms targeting different switch behaviors.
Question 6Choose Two
Which two statements about ARP poisoning are correct? (Choose two.)
ARP poisoning relies on forged ARP replies exploiting ARP's lack of authentication, commonly impersonating the default gateway to redirect traffic.
Question 7Scenario
A website suddenly becomes unreachable after being flooded with traffic from thousands of different source IP addresses simultaneously. What is this most likely an example of?
Traffic from thousands of distinct sources simultaneously is the defining characteristic of a DDoS attack.
Question 8Scenario
A switch that normally forwards traffic only to its intended destination port suddenly starts sending all traffic to every port. What has most likely occurred?
A switch reverting to broadcasting traffic out every port is the classic sign of a successful MAC flooding attack overflowing its MAC table.
Question 9Scenario
A device's ARP table shows the default gateway's IP address mapped to an unfamiliar MAC address that keeps changing. What does this suggest?
An unfamiliar, changing MAC address for the gateway's IP is a strong indicator of ARP poisoning in progress.
Question 10Scenario
A user types a completely correct, familiar domain name but lands on a suspicious site that isn't the legitimate one. What attack does this most likely describe?
A correctly typed domain resolving to the wrong address points to DNS poisoning corrupting the resolution process, not a typo or user error.
Question 11Scenario
An investigation reveals that an employee's traffic was secretly routed through an attacker's laptop before reaching its real destination, without the employee noticing. What type of attack is this?
Traffic secretly routed through an attacker's device is exactly an on-path attack, and ARP poisoning is a common mechanism used to set this up.
Question 12Exhibit
Based on this traffic log, what type of attack is occurring?
Traffic Log: Target: web-srv-01.example.com Source IP: 203.0.113.45 (single source) Request Volume: 500,000 requests/second, sustained
A single source IP generating overwhelming traffic volume is a classic single-source DoS attack, not distributed.
Question 13Exhibit
Based on this traffic log, what type of attack is occurring?
Traffic Log: Target: web-srv-01.example.com Unique Source IPs Observed: 48,000+ distinct addresses Request Pattern: Coordinated, simultaneous flood
Tens of thousands of distinct source IPs flooding simultaneously is the signature of a DDoS attack.
Question 14Exhibit
Based on this switch log, what attack is indicated?
Switch Log: MAC Address Table: FULL (16,384 / 16,384 entries) Entries: Majority appear randomly generated, never seen before Current Mode: Flooding traffic to all ports
A full MAC table with mostly bogus, never-seen-before entries, combined with the switch flooding all ports, is exactly the signature of a MAC flooding attack.
Question 15Exhibit
Based on this ARP table, what is happening?
ARP Table Log: 10:00:01 — 192.168.1.1 (gateway) -> AA:BB:CC:11:22:33 (known legitimate) 10:00:15 — 192.168.1.1 (gateway) -> DE:AD:BE:EF:00:99 (unrecognized, unexpected change) 10:00:30 — 192.168.1.1 (gateway) -> DE:AD:BE:EF:00:99 (unchanged)
The gateway's known legitimate MAC suddenly changing to an unrecognized address is a clear ARP poisoning indicator.
Question 16Exhibit
Based on this DNS cache entry, what has occurred?
DNS Cache Entry: Domain: mybank.example.com Expected IP: 203.0.113.10 (legitimate) Cached IP: 198.51.100.66 (attacker-controlled, confirmed via investigation)
A legitimate domain resolving to a confirmed attacker-controlled IP in the cache is exactly DNS poisoning.
Question 17Exhibit
Based on this packet capture path analysis, what attack type is indicated?
Path Analysis: Expected path: Client -> Router -> Internet Actual path observed: Client -> Attacker Laptop -> Router -> Internet Attacker Laptop: Not a legitimate network device
Traffic detouring through an illegitimate device before reaching its real destination is exactly an on-path attack.
📝

Summary

DoS attacks overwhelm a target from a single source; DDoS attacks do the same from many distributed sources, making them far harder to block — both directly attack availability.

VLAN hopping lets traffic cross into a VLAN it shouldn't reach, often via misconfigured trunk ports; MAC flooding overwhelms a switch's MAC table, forcing it to broadcast traffic like a hub.

ARP poisoning exploits ARP's lack of authentication to redirect traffic through an attacker by forging replies, commonly impersonating the default gateway.

DNS poisoning corrupts name resolution so a correctly typed, legitimate domain resolves to an attacker-controlled address instead of the real one.

On-path attacks intercept communication between two parties, and they're frequently the actual objective that ARP poisoning or a rogue access point is used to set up

Avatar Of Asad Ijaz

Lead Networking Architect and Editor at NetworkUstad. BS in Computer Networks and Security, CCNP and CCNA certified, with 11+ years of experience in enterprise network design, implementation, and troubleshooting. Writes practical tutorials on routing, IPv4 management, network automation, and security fundamentals.