⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE [L2] Networking Production Scenario [L2]

Q: In a corporate network, an attacker executes a malicious script that generates millions of random fake MAC addresses and rapidly fills up the network switch's CAM table (MAC address table). What happens to the switch, and what security risk does this open?

This is a MAC Flooding attack.

#Networking #Networking #L2 #VPC #DNS #Security
🎙️ Candidate Opening & Architectural Context
""In our multi-VPC setup, services in private subnets ran into this exact routing obstacle. The interviewer is testing: MAC Flooding, fail-open behavior of switches.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Production Solution & Architecture

This is a MAC Flooding attack. A switch has a limited amount of memory to map MAC addresses to physical ports. When the attacker's script completely exhausts this memory, the switch can no longer remember where legitimate devices are plugged in. When a switch doesn't know where to send a packet, its default fail-safe protocol is to "fail-open" and act like a Hub. It broadcasts every single incoming packet out of *every single port* on the switch. The security risk is catastrophic: the attacker can now run a packet sniffer (like Wireshark) on their laptop and passively see all horizontal traffic intended for other computers, intercepting plaintext passwords and sessions. (Mitigated by configuring Switch Port Security algorithms limiting MACs per physical port).

💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: This is a MAC Flooding attack.."
⚡ 60-Second Elevator Pitch Talking Points
  • Immediate Triage: This is a MAC Flooding attack.
  • Run targeted verification commands before modifying configuration.
  • Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement
Want more Networking scenarios?
Explore our complete collection of scenario-based Networking interview runbooks.
Browse All Networking Questions →

📚 Related Production Scenarios in Networking