CompTIA CySA+ (CS0-003)Security OperationsMedium
Employees on a corporate segment suddenly lose network connectivity. An analyst captures traffic and sees that for a single DHCPDISCOVER broadcast, two DHCPOFFER messages are returned from two different MAC addresses, one of which is not on the approved switch port list, and clients receiving that offer are assigned an incorrect default gateway. Which activity does this indicate?
- ADNS spoofing
- BARP spoofing
- CDHCP starvation attack
- DRogue DHCP server
Show answer & explanationAnswer & explanation
Correct answer: D. Rogue DHCP server
An unauthorized device answering DHCP requests with its own configuration (often pointing clients to a malicious gateway) is a rogue DHCP server, typically used to enable man-in-the-middle attacks. DHCP starvation floods the legitimate server with fake requests to exhaust its address pool rather than issuing false offers itself, and ARP/DNS spoofing operate on different protocols.
Why the other options are wrong
- A. DNS spoofing forges DNS responses, unrelated to DHCP offers.
- B. ARP spoofing manipulates the ARP cache, not DHCP lease negotiation.
- C. Starvation consumes the DHCP pool via many fake DISCOVER requests, it does not itself send offers with bad gateways.
Rogue DHCP Server
An unauthorized device on the network that responds to DHCP requests with its own lease information, often redirecting victims' default gateway or DNS server to attacker-controlled infrastructure.
- Detected by seeing multiple DHCPOFFER from unexpected MAC/switch ports
- Mitigated with DHCP snooping on switches
- Often paired with man-in-the-middle attacks
Memory trick: 'Rogue offers a fake key to your door' - a second, unauthorized DHCPOFFER hands out a bad gateway.