Which command or tool would a network engineer use to verify if a client has a duplicate IP address conflict on the local subnet?
arp -a displays the system's ARP cache, which maps IPv4 addresses to MAC addresses for hosts reached on the local subnet. When two devices are using the same IP, the cache may show two different MAC addresses for that same IP, or the mapping may flip back and forth between the two entries as traffic is sent. Examining the ARP table for inconsistent or changing MAC-to-IP pairings is a classic method for detecting an IP address conflict.
Why this answer
The two tools to verify a duplicate IP conflict are arp -a and ping. The arp -a command displays the ARP cache; if a duplicate IP exists, the ARP table may show multiple MAC addresses for the same IP or rapid changes. Ping can be used to send traffic to the local IP address; if a reply is received from a different MAC address than expected, it indicates a conflict.
Together, these commands help network engineers confirm IP address duplication. Other commands like ipconfig /all, nslookup, and tracert do not directly reveal such conflicts.
Exam trap
A common misconception is that ipconfig /all can detect duplicate IPs, but it only displays local configuration. In reality, arp -a and ping are the key tools to identify IP conflicts at the network layer.
Why the other options are wrong
`ipconfig /all` shows only the local IP configuration, not whether the same IP is assigned to another host.
`nslookup` resolves domain names to IP addresses and is unrelated to local IP conflicts.
`tracert` traces the path to a remote host, irrelevant for detecting local subnet duplicate IPs.