nerdexam
CompTIA

SY0-501 · Question #278

While performing surveillance activities, an attacker determines that an organization is using 802.1X to secure LAN access. Which of the following attack mechanisms can the attacker utilize to…

The correct answer is A. MAC spoofing. An attacker can utilize MAC spoofing to bypass 802.1X network security by impersonating an authenticated device's MAC address, potentially gaining unauthorized LAN access.

Submitted by klara.se· Mar 4, 2026Threats, vulnerabilities, and mitigations

Question

While performing surveillance activities, an attacker determines that an organization is using 802.1X to secure LAN access. Which of the following attack mechanisms can the attacker utilize to bypass the identified network security?

Options

  • AMAC spoofing
  • BPharming
  • CXmas attack
  • DARP poisoning

How the community answered

(27 responses)
  • A
    81% (22)
  • B
    11% (3)
  • C
    4% (1)
  • D
    4% (1)

Why each option

An attacker can utilize MAC spoofing to bypass 802.1X network security by impersonating an authenticated device's MAC address, potentially gaining unauthorized LAN access.

AMAC spoofingCorrect

MAC spoofing can bypass 802.1X network security by allowing an attacker to impersonate the MAC address of an authenticated device on the network. This attack can succeed if the 802.1X authenticator is configured in multi-host mode, or if security measures like port security are not implemented to prevent unauthorized MACs from connecting to a port, potentially granting the attacker unauthorized LAN access.

BPharming

Pharming is a type of cyberattack that redirects users from legitimate websites to fraudulent ones, which is unrelated to bypassing 802.1X LAN access control.

CXmas attack

A Xmas attack is a reconnaissance technique used to scan for open ports on a system, not a mechanism to bypass network access authentication like 802.1X.

DARP poisoning

ARP poisoning is a technique used to manipulate network traffic after an attacker has already gained access to the network, rather than a method to bypass initial 802.1X authentication for LAN access.

Concept tested: 802.1X vulnerabilities and bypass techniques

Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3750/software/release/12-2_52_se/configuration/guide/3750scg/sw8021x.html

Topics

#802.1X#MAC spoofing#network access control#authentication bypass

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice