Identifying ARP Poisoning from MAC and Traffic Clues
A server administrator is reporting performance issues when accessing all internal resources. Upon further investigation, the security team notices the following: • A user's endpoint has been compromised and is broadcasting its MAC as the default gateway's MAC throughout the LAN. • Traffic to and from that endpoint is significantly greater than all other similar endpoints on the LAN. • Network ports on the LAN are not properly configured. • Wired traffic is not being encrypted properly. Which of the following attacks is most likely occurring?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the ability to correlate endpoint compromise, excessive traffic volume, and gateway MAC spoofing to identify ARP poisoning versus other LAN-layer attacks like MAC flooding or DDoS.
This question identifies an active Man-in-the-Middle attack characterized by MAC spoofing of the default gateway. The correct answer is C (ARP poisoning), distinguished by the broadcast of a false MAC address to intercept internal traffic.
Learners often select B (MAC flooding) because it involves MAC addresses, but MAC flooding targets the switch's CAM table rather than spoofing a specific device's identity to intercept traffic.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The scenario describes a classic ARP poisoning attack where a compromised host broadcasts unsolicited ARP replies to associate its own MAC address with the IP address of the default gateway. This allows the attacker to intercept traffic intended for the gateway, resulting in significantly higher traffic volume on that endpoint compared to others. Since ARP lacks built-in authentication, receiving devices trust the spoofed reply and update their local cache, enabling the Man-in-the-Middle position.Why the Other Options Are Wrong
Option A (DDoS) typically involves overwhelming a target with traffic from multiple sources or a botnet, not necessarily spoofing a gateway MAC. Option B (MAC flooding) aims to overflow the switch's Content Addressable Memory (CAM) table to force the switch into hub mode, which differs from the specific gateway impersonation described here. Option D (DHCP snooping) is a security feature used to prevent rogue DHCP servers, not an attack vector itself.Community Comment Notes
The community consensus strongly supports ARP poisoning, citing the mechanism of associating a fake MAC with the gateway IP. As Erfan noted, "In an ARP poisoning attack, the attacker sends false ARP messages to associate their MAC address with the IP address of the default gateway." Another commenter emphasized that "Arp poisoning" works by broadcasting unsolicited replies that devices trust due to the protocol's lack of security mechanisms.Exam Strategy
When analyzing network attacks, look for keywords like 'spoofing,' 'masquerading,' or 'intercepting' combined with Layer 2 protocols (ARP, MAC). If traffic is being redirected to a single compromised host acting as a gateway, think ARP poisoning first.
Frequently Asked Questions
How does ARP poisoning differ from MAC flooding?
MAC flooding overflows the switch's CAM table to force hub mode, while ARP poisoning spoofs IP-to-MAC mappings to intercept traffic between specific hosts.
Why is DHCP snooping not the correct answer?
DHCP snooping is a defensive configuration feature, not an attack. It prevents rogue DHCP servers from distributing incorrect IP configurations.