Duplicate MAC Addresses in Network Audits | SY0-601
A security analyst finds a rogue device during a monthly audit of current endpoint assets that are connected to the network. The corporate network utilizes 802.1 X for access control. To be allowed on the network, a device must have a known hardware address, and a valid username and password must be entered in a captive portal. The following is the audit report: Which of the following is the most likely way a rogue device was allowed to connect? - 
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests recognition of MAC spoofing indicators in network logs, where identical hardware addresses across different hostnames signal unauthorized device replication to bypass 802.1X authentication.
Identifies how duplicate MAC addresses in endpoint audit reports reveal a MAC cloning attack, explaining why option A is the correct answer for SY0-601. Establishes that identical Layer 2 identifiers across separate hostnames directly indicate hardware address spoofing rather than configuration errors.
Candidates often select DHCP or DNS options when seeing duplicate IP addresses or mismatched hostnames, but they overlook that matching MAC addresses specifically indicate MAC cloning rather than routine network assignment faults.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The audit report displays two distinct hostnames, PC-CA and WIN10, sharing the exact same MAC address (00-1B-44-11-3A-B3). Since 802.1X enforces network access through credential and hardware verification, duplicate Layer 2 identifiers across separate endpoints strongly indicate MAC cloning. A malicious actor or policy-violating user copied the authorized corporate device’s hardware address onto an unregistered personal computer to bypass authentication restrictions.Why the Other Options Are Wrong
DHCP failures typically result in APIPA ranges or subnet mismatches, not identical hardware addresses across different machines. Administrator testing bypasses would generate explicit exception logs or temporary account flags rather than spontaneous MAC duplication. DNS hijacking manipulates domain name resolution at Layer 3 and cannot fabricate or replicate physical NIC identifiers visible in switch port audits.Community Comment Notes
Learners consistently identified the shared MAC value as the primary clue, with multiple users noting that the overlapping identifier between PC-CA and WIN10 confirms hardware spoofing. As one contributor summarized, the duplicate MAC address directly points to MAC cloning rather than routine network configuration issues. Another commenter emphasized that Windows hostname conventions combined with matching hardware addresses rule out accidental assignment errors.Exam Strategy
Always cross-reference Layer 2 identifiers before assuming Layer 3 issues like DHCP scope exhaustion; duplicate MACs in audit logs immediately point to MAC spoofing or cloning attempts. When analyzing endpoint inventory tables, prioritize hardware address consistency to quickly detect unauthorized device replication on secured networks.
Frequently Asked Questions
Why does a duplicate MAC address prove MAC cloning instead of a DHCP error?
DHCP handles Layer 3 IP assignments, while MAC addresses are hardcoded at Layer 2; identical MACs on separate hostnames confirm intentional hardware ID replication, not network configuration faults.
How does 802.1X prevent MAC cloning attacks in enterprise environments?
Modern 802.1X implementations use EAP-TLS with machine certificates rather than relying solely on MAC authentication, making cloned hardware addresses ineffective against credential-based validation.