Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisHard
A security analyst is investigating a network segment and notices a significant increase in ARP requests and responses, with multiple MAC addresses being associated with the same IP address over a short period. This activity is occurring on a local subnet and is causing intermittent connectivity issues for legitimate hosts. What type of network attack is most likely taking place?
- ADHCP Starvation
- BDNS Spoofing
- CIP Fragmentation Attack
- DARP Spoofing/Poisoning
Show answer & explanationAnswer & explanation
Correct answer: D. ARP Spoofing/Poisoning
ARP spoofing (or poisoning) involves an attacker sending forged ARP messages to associate their MAC address with another device's IP address, leading to incorrect ARP table entries and allowing the attacker to intercept or disrupt traffic.
Why the other options are wrong
- A. DHCP starvation exhausts the DHCP server's IP address pool, preventing new hosts from getting IPs, which is different from ARP table manipulation.
- B. DNS spoofing involves altering DNS records to redirect traffic, not manipulating ARP entries or causing intermittent connectivity via ARP.
- C. IP fragmentation attacks exploit how IP packets are reassembled; they do not directly involve ARP requests or MAC address association issues.
ARP Spoofing/Poisoning
ARP spoofing (or ARP poisoning) is a type of attack in which a malicious actor sends falsified ARP (Address Resolution Protocol) messages over a local area network. This results in the attacker's MAC address being linked to the IP address of a legitimate computer or server on the network.
- Manipulates ARP tables on hosts/switches
- Attacker sends forged ARP replies
- Associates attacker's MAC with another IP
- Enables Man-in-the-Middle (MitM) attacks or DoS
Memory trick: Layer 2 attacks are 'Sneaky Tricks' on the local network links.