200-201 Network Intrusion Analysis Practice Question
An analyst is investigating a suspected ARP poisoning attack on a local subnet. The analyst captures traffic and reviews ARP packets. Which two characteristics would most likely indicate that ARP poisoning is occurring? (Choose two.)
⚠ Common exam trap
The trap here is assuming that any broadcast ARP request is malicious, when in fact broadcast requests are normal; poisoning is signaled by unsolicited replies and MAC/IP mismatches.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Multiple ARP replies from the same MAC address claiming different IP addresses
The correct indicators are multiple ARP replies from one MAC claiming different IPs and gratuitous ARP replies not preceded by a request. Both are hallmarks of ARP poisoning, where an attacker floods the network with forged ARP mappings to intercept traffic. Normal ARP requests are broadcast and are not malicious. The other options describe normal or invalid but non-indicative behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ARP packets with a sender MAC address that is a multicast address
Why it's wrong here
ARP sender MAC addresses should be unicast addresses. A multicast MAC address in the sender field would be invalid and likely dropped by hosts. ARP poisoning typically uses the attacker's actual unicast MAC address, not a multicast address. This option is not a realistic indicator of ARP poisoning.
- ✗
ARP request packets with a broadcast destination MAC address
Why it's wrong here
ARP requests are normally broadcast to FF:FF:FF:FF:FF:FF to discover the MAC address of a target IP. This is standard ARP behavior and does not indicate poisoning. Poisoning involves unsolicited ARP replies or replies that map an IP to an incorrect MAC, not the normal broadcast requests used for resolution.
- ✓
Multiple ARP replies from the same MAC address claiming different IP addresses
Why this is correct
In ARP poisoning, an attacker sends gratuitous ARP replies to associate their MAC address with multiple IP addresses, or to impersonate the gateway. Seeing a single MAC address claiming ownership of several IPs is a strong indicator. Legitimate hosts typically have one IP per MAC address (or a few in specific configurations), so this behavior is suspicious.
- ✗
ARP requests sent to a unicast destination MAC address
Why it's wrong here
ARP requests are generally broadcast, but they can be unicast in some cases (e.g., ARP probes). However, this is not an indicator of poisoning. Poisoning relies on replies that update caches, not on the destination of requests. Unicast ARP requests are uncommon but not malicious by themselves.
- ✓
Gratuitous ARP replies that are not preceded by an ARP request
Why this is correct
Gratuitous ARP replies are sent without a corresponding request to update other hosts' ARP caches. While they can be legitimate (e.g., when a NIC comes up), a sudden increase in unsolicited ARP replies, especially mapping the gateway IP to a different MAC, is a classic sign of ARP poisoning. Attackers use this to redirect traffic through their machine.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.