ALL PASS, NO FAIL!

CEH v13 Module 8: Sniffing & Traffic Analysis — Free Practice Questions with Explanations

Last updated September 2026 · 10 questions · Module 8 of 20

Network interception: ARP spoofing, DNS poisoning, SSL stripping, packet capture, and traffic analysis techniques. Exam focus: ARP spoofing anchors this module. Understand how interception works on flat Layer 2 segments versus switched networks, what span and port mirroring add, and which Wireshark filter proves the attack.

⚠️ Important Disclaimer: These practice questions are original study material created by CEHStudy for educational purposes. They are NOT EC-Council exam questions and do NOT replicate the actual exam. CEHStudy is not affiliated with or endorsed by EC-Council.

Question 1: Network sniffing is:

Answer: B — Sniffers (Wireshark, tcpdump) capture packets for legitimate troubleshooting or malicious credential theft.

Question 2: ARP poisoning enables sniffing on switched networks by:

Answer: C — Fake ARP replies convince hosts to send frames to the attacker's MAC — establishing a Man-in-the-Middle position.

Question 3: A MAC flooding attack causes a network switch to:

Answer: D — Thousands of fake MAC addresses exhaust the address table; the switch then floods everything out all ports, enabling sniffing.

Question 4: In a DHCP starvation attack, the attacker:

Answer: B — Once the real DHCP server has no addresses left, the rogue server can point victims at attacker-controlled IPs/DNS.

Question 5: Which tool is a command-line packet capture utility for Linux and macOS?

Answer: A — tcpdump captures packets from the CLI; Wireshark offers the graphical deep-analysis environment.

Question 6: Traffic analysis differs from reading packet contents because it:

Answer: D — Even fully encrypted traffic leaks metadata: timing, sizes, and counterparties can reveal sensitive relationships.

Question 7: SSLStrip is used to:

Answer: D — A passive MITM rewrites links and intercepts the first HTTP request before the browser negotiates TLS.

Question 8: Why is sniffing more difficult on switched networks than on hubs?

Answer: C — Hubs flood everything; switches use MAC tables — so attackers need ARP poisoning, MAC flooding, or mirroring to capture others' traffic.

Question 9: Bettercap is best described as:

Answer: D — Bettercap bundles ARP spoofing, MITM modules, session hijacking, and traffic analysis into one framework (like Cain & Abel on Windows).

Question 10: Port mirroring (SPAN) enables sniffing by:

Answer: A — A legitimate admin feature — abused when access to the switch config is obtained, it quietly duplicates any conversation for capture.

Related Glossary Terms

Continue Your CEH v13 Prep

Frequently Asked Questions

How many CEH v13 Sniffing & Traffic Analysis practice questions are on this page?

This page includes 10 original multiple-choice practice questions for CEH v13 Module 8 (Sniffing & Traffic Analysis). Each question includes a detailed explanation of the correct answer and why the other options are wrong. The full CEHStudy question bank covers all 20 modules with 200+ questions — see the practice hub at https://cehstudy.com/ceh-practice-questions/ for every module.

What does CEH v13 Module 8 (Sniffing & Traffic Analysis) cover?

Network interception: ARP spoofing, DNS poisoning, SSL stripping, packet capture, and traffic analysis techniques. These are the same topics tested under this module on the EC-Council 312-50 exam. Pair this quiz with our free Module 8 flashcards at https://cehstudy.com/ceh-v13/module-08/ to close any gaps.

Are these real CEH exam questions?

No. Every question on CEHStudy is original study material written for exam preparation. They match the style, difficulty, and domain coverage of the actual CEH v13 exam but are not leaked or reproduced EC-Council questions.

How should I use this Sniffing & Traffic Analysis quiz for exam prep?

Answer all 10 questions without peeking at explanations, then click "Show My Score". Review every explanation — especially the ones you missed — and re-test those topics with our free CEH flashcards. Aim for 80% or higher on module quizzes before scheduling the exam.

Where do I find CEH Sniffing & Traffic Analysis flashcards?

Our free flashcard app covers all 20 CEH v13 modules including Module 8 (Sniffing & Traffic Analysis). Visit the CEH flashcards page at https://cehstudy.com/ or the Module 8 page at https://cehstudy.com/ceh-v13/module-08/. No account or sign-up required.