200-201 Security Concepts Practice Question
A security analyst is investigating a potential data breach. The analyst identifies that the attacker used a technique to impersonate a legitimate user by spoofing the MAC address and IP address. Which TWO types of network attacks could involve these techniques? (Choose two.)
⚠ Common exam trap
Cisco often tests the distinction between IP spoofing (Layer 3) and ARP spoofing (Layer 2), and candidates may incorrectly assume that IP spoofing alone is sufficient for impersonation on a local network, forgetting that ARP resolution is required for actual traffic interception.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ARP spoofing
ARP spoofing (A) is correct because it works by sending forged ARP replies that map the attacker's MAC address to a legitimate user's IP address, effectively spoofing both MAC and IP to impersonate that user on the local subnet. IP spoofing (D) is correct because it involves crafting packets with a forged source IP address (and often a spoofed MAC at layer 2) to make traffic appear to originate from a legitimate host. Denial of Service (B) focuses on exhausting resources or bandwidth rather than impersonating a user via MAC/IP spoofing. DNS poisoning (C) corrupts DNS resolver cache entries to redirect name resolution, not to impersonate a user's MAC/IP identity. Phishing (E) is a social-engineering attack using deceptive messages or sites, not MAC/IP address spoofing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ARP spoofing
Why this is correct
ARP spoofing sends forged Address Resolution Protocol replies, binding the attacker's MAC address to a legitimate user's IP address within the victim's cache. This satisfies the stem's requirement for both MAC and IP impersonation, enabling traffic interception or man-in-the-middle positioning on the local subnet.
- ✗
Denial of Service
Why it's wrong here
Denial of Service floods or exhausts a target's resources; spoofed MAC and IP addresses may hide the source, but the attack's purpose is service disruption, not impersonating a legitimate user to gain access. It is tempting because spoofing is genuinely used in DoS, and it would be correct if availability loss were the observed impact.
- ✗
DNS poisoning
Why it's wrong here
DNS poisoning corrupts resolver cache records to redirect name resolution; it does not spoof a host's MAC and IP addresses to impersonate that user on the local network. It is tempting because it also redirects traffic deceptively, and it would be correct if tampered DNS responses were the evidence.
- ✓
IP spoofing
Why this is correct
IP spoofing forges the source IP address in packet headers so traffic appears to originate from a trusted host, satisfying the stem's IP impersonation element. Combined with MAC spoofing, it supports session hijacking and bypassing address-based trust.
- ✗
Phishing
Why it's wrong here
Phishing is a social-engineering credential-theft technique delivered by email or messaging; it does not involve spoofing MAC or IP addresses at the network layer. It is tempting because phishing also impersonates a legitimate user, and it would be correct if the evidence were a deceptive message rather than spoofed addresses.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.