Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium

A security analyst is reviewing a packet capture from an internal network segment. They observe a high volume of ARP requests and replies, where multiple MAC addresses are being associated with a single IP address, and vice-versa. This is causing intermittent connectivity issues for several users on the segment. What type of attack is most likely occurring?

  1. ADHCP starvation
  2. BARP spoofing/poisoning
  3. CDNS cache poisoning
  4. DMAC flooding
Show answer & explanation

Correct answer: B. ARP spoofing/poisoning

ARP spoofing (or ARP poisoning) involves an attacker sending forged ARP messages onto a local area network. This results in the attacker's MAC address being associated with the IP address of another host (e.g., the default gateway) or multiple MAC addresses being associated with a single IP, leading to traffic interception or disruption, which aligns with the observed ARP anomalies and connectivity issues.

Why the other options are wrong

  • A. DHCP starvation exhausts the DHCP server's IP address pool, not by manipulating ARP entries.
  • C. DNS cache poisoning manipulates DNS resolution, not ARP entries on a local network segment.
  • D. MAC flooding overwhelms a switch's MAC address table, but it typically involves many unique MAC addresses, not multiple MACs for one IP or vice-versa.

ARP Spoofing/Poisoning

An attack technique where an attacker sends falsified ARP (Address Resolution Protocol) messages over a local area network to link their MAC address with the IP address of another legitimate host.

  • Allows attackers to intercept, modify, or stop traffic.
  • Often used as a prerequisite for Man-in-the-Middle attacks.
  • Can cause connectivity issues by misdirecting traffic.

Memory trick: Layer 2 attacks mess with local network addresses.

More Network Intrusion Analysis questions