Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityHard

A security engineer is analyzing a network where an attacker has successfully compromised an internal server and is now attempting to move laterally to other systems. The attacker is using Address Resolution Protocol (ARP) spoofing to redirect traffic from other internal hosts to their compromised server. Which network security measure can specifically detect and prevent such ARP-based attacks?

  1. APort Aggregation Protocol (PAgP)
  2. BSpanning Tree Protocol (STP)
  3. CInternet Group Management Protocol (IGMP) Snooping
  4. DDynamic ARP Inspection (DAI)
Show answer & explanation

Correct answer: D. Dynamic ARP Inspection (DAI)

Dynamic ARP Inspection (DAI) is a Layer 2 security feature on switches that validates ARP packets in an Ethernet network. It intercepts, logs, and discards ARP packets with invalid IP-to-MAC address bindings, effectively preventing ARP spoofing and poisoning attacks.

Why the other options are wrong

  • A. PAgP is used for EtherChannel creation, not ARP attack prevention.
  • B. STP prevents network loops, not ARP spoofing.
  • C. IGMP Snooping optimizes multicast traffic, not ARP security.

Dynamic ARP Inspection (DAI)

A Layer 2 security feature that helps prevent ARP spoofing and ARP poisoning attacks by validating ARP packets in an Ethernet network.

  • Validates IP-to-MAC address bindings in ARP packets.
  • Requires a trusted DHCP snooping database for dynamic bindings.
  • Can be configured to drop or log invalid ARP packets.
  • Protects against man-in-the-middle attacks at Layer 2.

Memory trick: DAI: The network's ID checker for ARP requests, ensuring no fake IDs (IP-MAC pairs).

More Network Security questions