Promiscuous mode on a NIC allows the device to capture what?

Prepare for the Computer Hacking Forensic Investigator v11 exam. Study with flashcards and multiple choice questions. Each question includes hints and explanations. Get exam-ready efficiently!

Multiple Choice

Promiscuous mode on a NIC allows the device to capture what?

Explanation:
Promiscuous mode bypasses the usual receive filtering of a network interface. Normally a NIC accepts only frames addressed to its MAC (plus certain broadcast/multicast frames). When promiscuous mode is enabled, the NIC delivers every frame it sees to the operating system, allowing a packet-capturing tool to inspect all traffic on the local network segment. This is why it’s used for network analysis and forensic investigations—it reveals traffic that wouldn’t be visible if the NIC were filtering strictly by destination. Keep in mind that on switched networks you may still not see all traffic unless port mirroring or a TAP is used. This mode isn’t about encryption, and it doesn’t cause frames to be dropped; it simply increases the amount of traffic the capture software can access.

Promiscuous mode bypasses the usual receive filtering of a network interface. Normally a NIC accepts only frames addressed to its MAC (plus certain broadcast/multicast frames). When promiscuous mode is enabled, the NIC delivers every frame it sees to the operating system, allowing a packet-capturing tool to inspect all traffic on the local network segment. This is why it’s used for network analysis and forensic investigations—it reveals traffic that wouldn’t be visible if the NIC were filtering strictly by destination. Keep in mind that on switched networks you may still not see all traffic unless port mirroring or a TAP is used. This mode isn’t about encryption, and it doesn’t cause frames to be dropped; it simply increases the amount of traffic the capture software can access.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy