Courseiva

200-201 Network Intrusion Analysis Practice Question

A SOC analyst is investigating a suspected ARP poisoning attack on a local subnet. Which two indicators would most strongly support this conclusion? (Choose two.)

⚠ Common exam trap

The trap here is choosing generic connectivity symptoms such as retransmissions or DNS spikes instead of the ARP-specific evidence that directly shows cache manipulation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A high rate of unsolicited ARP replies on the subnet

ARP poisoning is confirmed by layer-2 evidence: multiple IP addresses resolving to one MAC address in the ARP cache, and a high volume of unsolicited ARP replies. DNS query spikes, duplicate IP conflict messages, and TCP retransmissions may accompany network problems but are not specific to forged ARP activity, so they do not strongly support the conclusion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A high rate of unsolicited ARP replies on the subnet

    Why this is correct

    Legitimate ARP is request-driven, so a flood of unsolicited ARP replies, especially gratuitous ones claiming an IP already in use, indicates an attacker updating victims' caches. This behavior is characteristic of ARP poisoning tools that continuously send forged replies. Detecting a high rate of unsolicited replies is a reliable network-level indicator.

  • ✗

    An increase in TCP retransmissions across the subnet

    Why it's wrong here

    TCP retransmissions can result from many causes such as congestion, duplex mismatch, or packet loss, and are not specific to ARP poisoning. Although poisoning can disrupt traffic, retransmissions alone do not demonstrate that ARP caches were manipulated. This indicator is too generic to support the conclusion.

  • ✓

    Multiple IP addresses mapping to the same MAC address in the ARP cache

    Why this is correct

    ARP poisoning causes a single attacker MAC address to be associated with multiple IP addresses as the attacker claims to be the gateway or other hosts. Seeing several IPs resolve to one MAC in the ARP cache is a direct indicator that ARP replies have been spoofed. This is one of the strongest host-level signs of an active poisoning attack.

  • ✗

    Duplicate IP address conflict messages in system logs

    Why it's wrong here

    Duplicate IP conflict messages usually indicate static misconfiguration or DHCP conflicts, not ARP poisoning. While poisoning can cause connectivity issues, the conflict message itself is not a specific indicator of forged ARP replies. Relying on it would produce false positives in environments with legitimate address conflicts.

  • ✗

    A sudden increase in DNS query volume from a single host

    Why it's wrong here

    ARP poisoning operates at layer 2 and does not inherently increase DNS query volume. A spike in DNS queries may indicate malware, but it is not a direct indicator of ARP cache manipulation. This option confuses a higher-layer symptom with the layer-2 attack being investigated.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.