Identifying ARP Poisoning from MAC and Traffic Clues

Answer Correct answer: C — The attack is identified as ARP poisoning due to the spoofing of the default gateway's MAC address to intercept and manipulate internal LAN traffic.

A server administrator is reporting performance issues when accessing all internal resources. Upon further investigation, the security team notices the following: • A user's endpoint has been compromised and is broadcasting its MAC as the default gateway's MAC throughout the LAN. • Traffic to and from that endpoint is significantly greater than all other similar endpoints on the LAN. • Network ports on the LAN are not properly configured. • Wired traffic is not being encrypted properly. Which of the following attacks is most likely occurring?

  1. DDoS
  2. MAC flooding
  3. ARP poisoning Correct Answer
  4. DHCP snooping

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the ability to correlate endpoint compromise, excessive traffic volume, and gateway MAC spoofing to identify ARP poisoning versus other LAN-layer attacks like MAC flooding or DDoS.

This question identifies an active Man-in-the-Middle attack characterized by MAC spoofing of the default gateway. The correct answer is C (ARP poisoning), distinguished by the broadcast of a false MAC address to intercept internal traffic.

Learners often select B (MAC flooding) because it involves MAC addresses, but MAC flooding targets the switch's CAM table rather than spoofing a specific device's identity to intercept traffic.

Community Discussion (5 comments)

Mizzcoors 👍 3 Selected: C
An ARP poisoning attack uses a packet crafter, such as Ettercap, to broadcast unsolicited ARP reply packets. Because ARP has no security mechanism, the receiving devices trust this communication and update their MAC:IP address cache table with the spoofed address. An attacker usually tries to masquerade as the default gateway
Benrosan 👍 1 Selected: C
Agree with ARP poisoning
Hs1208 👍 4 Selected: C
In an ARP poisoning attack, the attacker sends false ARP messages to associate their MAC address with the IP address of the default gateway or other devices on the network
maggie22 👍 1 Selected: C
It's ARP poisoning. Broadcasting its MAC as the dedfault gateway.
[Removed] 👍 4 Selected: C
Arp poisoning. here is a video. https://www.youtube.com/watch?v=A7nih6SANYs

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The scenario describes a classic ARP poisoning attack where a compromised host broadcasts unsolicited ARP replies to associate its own MAC address with the IP address of the default gateway. This allows the attacker to intercept traffic intended for the gateway, resulting in significantly higher traffic volume on that endpoint compared to others. Since ARP lacks built-in authentication, receiving devices trust the spoofed reply and update their local cache, enabling the Man-in-the-Middle position.

Why the Other Options Are Wrong

Option A (DDoS) typically involves overwhelming a target with traffic from multiple sources or a botnet, not necessarily spoofing a gateway MAC. Option B (MAC flooding) aims to overflow the switch's Content Addressable Memory (CAM) table to force the switch into hub mode, which differs from the specific gateway impersonation described here. Option D (DHCP snooping) is a security feature used to prevent rogue DHCP servers, not an attack vector itself.

Community Comment Notes

The community consensus strongly supports ARP poisoning, citing the mechanism of associating a fake MAC with the gateway IP. As Erfan noted, "In an ARP poisoning attack, the attacker sends false ARP messages to associate their MAC address with the IP address of the default gateway." Another commenter emphasized that "Arp poisoning" works by broadcasting unsolicited replies that devices trust due to the protocol's lack of security mechanisms.

Exam Strategy

When analyzing network attacks, look for keywords like 'spoofing,' 'masquerading,' or 'intercepting' combined with Layer 2 protocols (ARP, MAC). If traffic is being redirected to a single compromised host acting as a gateway, think ARP poisoning first.

Frequently Asked Questions

How does ARP poisoning differ from MAC flooding?

MAC flooding overflows the switch's CAM table to force hub mode, while ARP poisoning spoofs IP-to-MAC mappings to intercept traffic between specific hosts.

Why is DHCP snooping not the correct answer?

DHCP snooping is a defensive configuration feature, not an attack. It prevents rogue DHCP servers from distributing incorrect IP configurations.

Related Analysis

← Back to SY0-601 Study Guide