CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
An analyst reviewing switch logs on a local network segment notices that a host is flooding the network with thousands of ARP replies mapping the gateway's IP address to the attacker's MAC address. What is the primary goal of this activity?
- ATo perform a distributed denial-of-service attack
- BTo bypass network access control authentication
- CTo exhaust the switch's MAC address table
- DTo intercept traffic destined for the default gateway
Show answer & explanationAnswer & explanation
Correct answer: D. To intercept traffic destined for the default gateway
ARP poisoning (spoofing) tricks hosts on the local segment into sending traffic intended for the gateway to the attacker's MAC address instead, enabling an on-path (man-in-the-middle) attack.
Why the other options are wrong
- A. DDoS aims to overwhelm availability, not redirect specific traffic paths.
- B. ARP poisoning does not target NAC authentication mechanisms.
- C. That describes MAC flooding, a different attack targeting the CAM table, not ARP spoofing.
ARP Poisoning
An attack where forged ARP replies associate the attacker's MAC address with a legitimate IP (often the gateway), redirecting local traffic to the attacker.
- Enables on-path (MITM) attacks on LANs
- Exploits lack of ARP authentication
- Mitigated by dynamic ARP inspection and static ARP entries
Memory trick: ARP poisoning hijacks the address book so mail goes to the wrong desk.