Domain 4.0 | Network Security — 14% of exam
Learning Objectives
By the end of this lesson, you will be able to:
- Explain DoS and DDoS attacks and how they specifically target availability
- Describe VLAN hopping and MAC flooding as attacks targeting switch behavior
- Explain ARP poisoning/spoofing and how it redirects traffic through an attacker
- Explain DNS poisoning/spoofing and its impact on legitimate name resolution
- Describe on-path attacks and how earlier attacks in this lesson often enable them
Key Terms – Network-Based Attacks
| Term | Definition |
|---|---|
| DoS (Denial of Service) | An attack from a single source that overwhelms a target, denying service to legitimate users |
| DDoS (Distributed Denial of Service) | A DoS attack launched from many distributed sources simultaneously, making it far harder to block |
| VLAN Hopping | An attack technique allowing traffic to reach a VLAN the attacker shouldn’t have access to |
| MAC Flooding | Overflowing a switch’s MAC address table with bogus entries, causing it to fail open and broadcast traffic like a hub |
| On-Path Attack | An attack where the attacker intercepts communication between two parties, often enabled by ARP poisoning or a rogue access point |
Explanation
From Security Concepts to Active Attacks
Objective 4.1 covered foundational security concepts — the CIA triad, certificates, identity management, and segmentation. This lesson shifts to the active side: specific attack techniques that directly target the network itself, several of which build on each other in ways worth understanding as a connected sequence rather than a disconnected list.
DoS and DDoS: Attacking Availability
A DoS (Denial of Service) attack overwhelms a target — a server, a service, a network link — with traffic or requests from a single source, consuming enough resources that legitimate users can no longer get through. This is a direct, textbook attack on the availability property of the CIA triad — the data itself might remain perfectly confidential and unmodified, but the service becomes unreachable regardless.A DDoS (Distributed Denial of Service) attack is the same basic idea scaled up dramatically: instead of one source, traffic floods in from many distributed sources simultaneously — often a large network of compromised devices (a botnet) — making the attack both far more powerful and far harder to block, since there’s no single source IP to simply filter out.

VLAN Hopping and MAC Flooding: Attacking Switches
Two distinct attack techniques target switch behavior specifically:
VLAN hopping lets an attacker’s traffic reach a VLAN they shouldn’t have legitimate access to, commonly by exploiting a misconfigured trunk port or by crafting frames that manipulate how VLAN trunking and tagging is processed. Properly securing trunk port configuration and avoiding unnecessary default VLAN assignments significantly reduces this risk. MAC flooding targets a switch’s MAC address table (also called its CAM table) directly, overwhelming it with a flood of bogus, fabricated MAC addresses until the table fills up completely. Once that happens, many switches respond by failing open — reverting to broadcasting all traffic out every port, essentially behaving like a hub rather than a switch — which lets an attacker capture traffic on the network segment they’d otherwise never see, since normal switch behavior would only forward traffic to its intended destination port.
Both attacks share a common theme: exploiting how switches are designed to behave under specific conditions, turning a normal operational mechanism into an opportunity for unauthorized access or traffic interception.
ARP Poisoning and Spoofing
ARP poisoning (also called ARP spoofing) exploits the fact that ARP has no built-in authentication: an attacker sends forged ARP replies claiming that their own MAC address corresponds to another device’s IP address — very often the network’s default gateway. Devices on the local segment update their ARP tables based on these forged replies without verifying them, and traffic that should have gone to the real gateway instead gets sent to the attacker first.

Once traffic is flowing through the attacker this way, they can read it, modify it, or simply forward it along to the real destination after inspecting it — the victim typically has no immediate indication anything is wrong, since their connection still appears to work normally.
DNS Poisoning and Spoofing
DNS poisoning (or DNS spoofing) corrupts DNS resolution so that a legitimate domain name resolves to an attacker-controlled IP address instead of the real one. This can happen by corrupting a resolver’s cache with a forged response, or by intercepting and forging a DNS response before the legitimate one arrives. The practical effect is that a user typing in a completely correct, legitimate domain name still ends up connecting to an attacker’s server instead of the real one — the domain name itself was never wrong, but the resolution behind it was compromised.On-Path Attacks: The Common Destination
An on-path attack (also known as a man-in-the-middle attack) describes any situation where an attacker successfully inserts themselves between two communicating parties, intercepting — and potentially altering — traffic passing between them. This is worth covering last in this lesson specifically because it’s often the actual goal several of the previous techniques are working toward: ARP poisoning is frequently used specifically to position an attacker for an on-path attack, and a rogue access point can achieve a similar result in a wireless context by tricking clients into routing their traffic through the attacker in the first place.
Recognition-Level Verification Concepts
A few patterns are worth recognizing on sight:
- Traffic arriving from one specific IP address overwhelming a target describes DoS; traffic arriving from many distributed IP addresses simultaneously describes DDoS.
- Traffic unexpectedly reaching a VLAN it shouldn’t have access to, especially via a trunk port, points to VLAN hopping.
- A switch suddenly broadcasting traffic to every port instead of only the intended destination points to a MAC flooding attack having succeeded.
- A device’s ARP table showing the default gateway’s IP mapped to an unfamiliar or incorrect MAC address is a strong sign of ARP poisoning in progress.
- A correctly typed, legitimate domain name resolving to an unexpected or suspicious IP address points to DNS poisoning, not a typo or user error.
Common Exam Traps
- DoS and DDoS differ specifically in source distribution, not overall goal. Both aim to deny service; the “distributed” part of DDoS is what makes it dramatically harder to block by simply filtering a single source.
- VLAN hopping and MAC flooding target different switch mechanisms. VLAN hopping crosses logical segment boundaries; MAC flooding forces the switch into broadcasting behavior — don’t conflate the two just because both target switches.
- ARP has no built-in authentication, which is exactly why ARP poisoning works at all. Don’t assume ARP replies are inherently trustworthy just because they come from the local network segment.
- DNS poisoning corrupts resolution, not the domain name itself. The domain the user typed was correct; what they were routed to was not — this distinction matters for correctly diagnosing the actual point of compromise.
- On-path attacks are often the end goal that other techniques (ARP poisoning, rogue APs) are working toward, not a completely separate, unrelated attack category.
Lesson 4.2.1 Practice Quiz — Network-Based Attacks
17 questions covering DoS/DDoS, VLAN hopping, MAC flooding, ARP poisoning, DNS poisoning, and on-path attacks.
N10-009 · Domain 4.2Summary
DoS attacks overwhelm a target from a single source; DDoS attacks do the same from many distributed sources, making them far harder to block — both directly attack availability.
VLAN hopping lets traffic cross into a VLAN it shouldn't reach, often via misconfigured trunk ports; MAC flooding overwhelms a switch's MAC table, forcing it to broadcast traffic like a hub.
ARP poisoning exploits ARP's lack of authentication to redirect traffic through an attacker by forging replies, commonly impersonating the default gateway.
DNS poisoning corrupts name resolution so a correctly typed, legitimate domain resolves to an attacker-controlled address instead of the real one.
On-path attacks intercept communication between two parties, and they're frequently the actual objective that ARP poisoning or a rogue access point is used to set up



