CompTIA CySA+ (CS0-003)Security OperationsHard
An analyst examines a packet capture and notices the following ARP traffic on the internal LAN segment: 192.168.1.1 is-at AA:BB:CC:11:22:33 192.168.1.1 is-at DE:AD:BE:EF:00:01 192.168.1.1 is-at AA:BB:CC:11:22:33 192.168.1.1 is-at DE:AD:BE:EF:00:01 The legitimate gateway's known MAC address is AA:BB:CC:11:22:33. What is the most likely explanation and appropriate immediate response?
- ADHCP lease renewal causing temporary duplicate entries; no action needed
- BNormal NIC teaming failover on the gateway; update network documentation
- CARP spoofing/man-in-the-middle attack; isolate the host using the rogue MAC and enable dynamic ARP inspection
- DA switch loop causing broadcast storms; disable spanning tree protocol
Show answer & explanationAnswer & explanation
Correct answer: C. ARP spoofing/man-in-the-middle attack; isolate the host using the rogue MAC and enable dynamic ARP inspection
Conflicting ARP replies claiming the same IP (the gateway) maps to two different MAC addresses is the signature of ARP spoofing/cache poisoning used for man-in-the-middle attacks; the response is to isolate the rogue MAC's host and enable protections like dynamic ARP inspection (DAI).
Why the other options are wrong
- A. DHCP lease renewal affects IP-to-host assignment, not conflicting ARP IP-to-MAC claims for the gateway.
- B. NIC teaming failover would not alternate rapidly between MACs claiming the same IP in ARP replies visible on the wire like this.
- D. Spanning tree loops cause broadcast storms of frames, not conflicting ARP IP-to-MAC ownership claims; disabling STP would worsen loop risk.
ARP Spoofing
An attack where a malicious host sends forged ARP replies to associate its own MAC address with the IP address of another host (often the gateway), enabling man-in-the-middle interception.
- Detected by conflicting ARP entries for one IP
- Mitigated with Dynamic ARP Inspection (DAI) and static ARP entries
- Enables traffic interception, session hijacking, or DoS
Memory trick: Two MACs claiming one IP = an imposter wearing the gateway's mask.