CompTIA Network+ (N10-009)Network SecurityMedium

A user reports that all traffic destined for the default gateway seems to pass through a coworker's workstation first. Packet captures show that workstation replying to ARP requests claiming to own the gateway's IP address, with its own MAC address mapped to that IP in every host's ARP cache. Which attack is being performed?

  1. ARogue access point
  2. BARP spoofing
  3. CVLAN hopping
  4. DDNS poisoning
Show answer & explanation

Correct answer: B. ARP spoofing

ARP spoofing (ARP poisoning) sends forged ARP replies to associate the attacker's MAC address with a legitimate IP, such as the gateway, enabling an on-path (man-in-the-middle) position. DNS poisoning targets name resolution, VLAN hopping targets Layer 2 segmentation, and a rogue AP is a wireless issue.

Why the other options are wrong

  • A. A rogue AP is an unauthorized wireless access point, unrelated to ARP caches.
  • C. VLAN hopping crosses VLAN boundaries via tagging tricks.
  • D. DNS poisoning corrupts DNS records, not the ARP cache.

ARP Spoofing (ARP Poisoning)

An attack where forged ARP replies associate the attacker's MAC address with a legitimate IP (often the gateway), redirecting traffic through the attacker for interception.

  • Exploits ARP's lack of authentication
  • Enables on-path/man-in-the-middle attacks
  • Mitigated by Dynamic ARP Inspection and static ARP entries

Memory trick: Lie about who owns the gateway's IP.

More Network Security questions