200-201 Network Intrusion Analysis Practice Question
A SOC analyst is investigating a suspected ARP poisoning attack on a local subnet. Which two indicators would most strongly support this conclusion? (Choose two.)
⚠ Common exam trap
The trap here is choosing generic connectivity symptoms such as retransmissions or DNS spikes instead of the ARP-specific evidence that directly shows cache manipulation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A high rate of unsolicited ARP replies on the subnet
ARP poisoning is confirmed by layer-2 evidence: multiple IP addresses resolving to one MAC address in the ARP cache, and a high volume of unsolicited ARP replies. DNS query spikes, duplicate IP conflict messages, and TCP retransmissions may accompany network problems but are not specific to forged ARP activity, so they do not strongly support the conclusion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A high rate of unsolicited ARP replies on the subnet
Why this is correct
Legitimate ARP is request-driven, so a flood of unsolicited ARP replies, especially gratuitous ones claiming an IP already in use, indicates an attacker updating victims' caches. This behavior is characteristic of ARP poisoning tools that continuously send forged replies. Detecting a high rate of unsolicited replies is a reliable network-level indicator.
- ✗
An increase in TCP retransmissions across the subnet
Why it's wrong here
TCP retransmissions can result from many causes such as congestion, duplex mismatch, or packet loss, and are not specific to ARP poisoning. Although poisoning can disrupt traffic, retransmissions alone do not demonstrate that ARP caches were manipulated. This indicator is too generic to support the conclusion.
- ✓
Multiple IP addresses mapping to the same MAC address in the ARP cache
Why this is correct
ARP poisoning causes a single attacker MAC address to be associated with multiple IP addresses as the attacker claims to be the gateway or other hosts. Seeing several IPs resolve to one MAC in the ARP cache is a direct indicator that ARP replies have been spoofed. This is one of the strongest host-level signs of an active poisoning attack.
- ✗
Duplicate IP address conflict messages in system logs
Why it's wrong here
Duplicate IP conflict messages usually indicate static misconfiguration or DHCP conflicts, not ARP poisoning. While poisoning can cause connectivity issues, the conflict message itself is not a specific indicator of forged ARP replies. Relying on it would produce false positives in environments with legitimate address conflicts.
- ✗
A sudden increase in DNS query volume from a single host
Why it's wrong here
ARP poisoning operates at layer 2 and does not inherently increase DNS query volume. A spike in DNS queries may indicate malware, but it is not a direct indicator of ARP cache manipulation. This option confuses a higher-layer symptom with the layer-2 attack being investigated.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.