Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium
A security analyst is reviewing a packet capture from an internal network segment. They observe a high volume of ARP requests and replies, where multiple MAC addresses are being associated with a single IP address, and vice-versa. This is causing intermittent connectivity issues for several users on the segment. What type of attack is most likely occurring?
- ADHCP starvation
- BARP spoofing/poisoning
- CDNS cache poisoning
- DMAC flooding
Show answer & explanationAnswer & explanation
Correct answer: B. ARP spoofing/poisoning
ARP spoofing (or ARP poisoning) involves an attacker sending forged ARP messages onto a local area network. This results in the attacker's MAC address being associated with the IP address of another host (e.g., the default gateway) or multiple MAC addresses being associated with a single IP, leading to traffic interception or disruption, which aligns with the observed ARP anomalies and connectivity issues.
Why the other options are wrong
- A. DHCP starvation exhausts the DHCP server's IP address pool, not by manipulating ARP entries.
- C. DNS cache poisoning manipulates DNS resolution, not ARP entries on a local network segment.
- D. MAC flooding overwhelms a switch's MAC address table, but it typically involves many unique MAC addresses, not multiple MACs for one IP or vice-versa.
ARP Spoofing/Poisoning
An attack technique where an attacker sends falsified ARP (Address Resolution Protocol) messages over a local area network to link their MAC address with the IP address of another legitimate host.
- Allows attackers to intercept, modify, or stop traffic.
- Often used as a prerequisite for Man-in-the-Middle attacks.
- Can cause connectivity issues by misdirecting traffic.
Memory trick: Layer 2 attacks mess with local network addresses.