Duplicate MAC Addresses in Network Audits | SY0-601

Answer Correct answer: A — A user performed a MAC cloning attack with a personal device to impersonate a registered corporate endpoint and bypass 802.1X network access controls.

A security analyst finds a rogue device during a monthly audit of current endpoint assets that are connected to the network. The corporate network utilizes 802.1 X for access control. To be allowed on the network, a device must have a known hardware address, and a valid username and password must be entered in a captive portal. The following is the audit report: Which of the following is the most likely way a rogue device was allowed to connect? - image

  1. A user performed a MAC cloning attack with a personal device. Correct Answer
  2. A DHCP failure caused an incorrect IP address to be distributed
  3. An administrator bypassed the security controls for testing.
  4. DNS hijacking let an attacker intercept the captive portal traffic.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests recognition of MAC spoofing indicators in network logs, where identical hardware addresses across different hostnames signal unauthorized device replication to bypass 802.1X authentication.

Identifies how duplicate MAC addresses in endpoint audit reports reveal a MAC cloning attack, explaining why option A is the correct answer for SY0-601. Establishes that identical Layer 2 identifiers across separate hostnames directly indicate hardware address spoofing rather than configuration errors.

Candidates often select DHCP or DNS options when seeing duplicate IP addresses or mismatched hostnames, but they overlook that matching MAC addresses specifically indicate MAC cloning rather than routine network assignment faults.

Community Discussion (7 comments)

shady23 👍 1 Selected: A
A. A user performed a MAC cloning attack with a personal device.
MortG7 👍 1
A PC-CA & WIN10 have the same MAC...cloning or spoofing.
7308365 👍 3
A. MAC Cloning Host Naming Conventions and PC-CA and WIN 10 having the exact same MAC gives it away
johnabayot 👍 1 Selected: A
Mac cloning
licks0re 👍 3 Selected: A
The win10 machine is the personnal device.
Securityguy42 👍 1 Selected: A
"A" is the only answer that makes sense in this pic.
Hs1208 👍 1 Selected: A
. A user performed a MAC cloning attack with a personal device.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The audit report displays two distinct hostnames, PC-CA and WIN10, sharing the exact same MAC address (00-1B-44-11-3A-B3). Since 802.1X enforces network access through credential and hardware verification, duplicate Layer 2 identifiers across separate endpoints strongly indicate MAC cloning. A malicious actor or policy-violating user copied the authorized corporate device’s hardware address onto an unregistered personal computer to bypass authentication restrictions.

Why the Other Options Are Wrong

DHCP failures typically result in APIPA ranges or subnet mismatches, not identical hardware addresses across different machines. Administrator testing bypasses would generate explicit exception logs or temporary account flags rather than spontaneous MAC duplication. DNS hijacking manipulates domain name resolution at Layer 3 and cannot fabricate or replicate physical NIC identifiers visible in switch port audits.

Community Comment Notes

Learners consistently identified the shared MAC value as the primary clue, with multiple users noting that the overlapping identifier between PC-CA and WIN10 confirms hardware spoofing. As one contributor summarized, the duplicate MAC address directly points to MAC cloning rather than routine network configuration issues. Another commenter emphasized that Windows hostname conventions combined with matching hardware addresses rule out accidental assignment errors.

Exam Strategy

Always cross-reference Layer 2 identifiers before assuming Layer 3 issues like DHCP scope exhaustion; duplicate MACs in audit logs immediately point to MAC spoofing or cloning attempts. When analyzing endpoint inventory tables, prioritize hardware address consistency to quickly detect unauthorized device replication on secured networks.

Frequently Asked Questions

Why does a duplicate MAC address prove MAC cloning instead of a DHCP error?

DHCP handles Layer 3 IP assignments, while MAC addresses are hardcoded at Layer 2; identical MACs on separate hostnames confirm intentional hardware ID replication, not network configuration faults.

How does 802.1X prevent MAC cloning attacks in enterprise environments?

Modern 802.1X implementations use EAP-TLS with machine certificates rather than relying solely on MAC authentication, making cloned hardware addresses ineffective against credential-based validation.

Related Analysis

← Back to SY0-601 Study Guide