Courseiva
Network Intrusion Analysis →mediumMultiple Select

200-201 Network Intrusion Analysis Practice Question

An analyst is investigating a suspected ARP poisoning attack on a local subnet. The analyst captures traffic and reviews ARP packets. Which two characteristics would most likely indicate that ARP poisoning is occurring? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any broadcast ARP request is malicious, when in fact broadcast requests are normal; poisoning is signaled by unsolicited replies and MAC/IP mismatches.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multiple ARP replies from the same MAC address claiming different IP addresses

The correct indicators are multiple ARP replies from one MAC claiming different IPs and gratuitous ARP replies not preceded by a request. Both are hallmarks of ARP poisoning, where an attacker floods the network with forged ARP mappings to intercept traffic. Normal ARP requests are broadcast and are not malicious. The other options describe normal or invalid but non-indicative behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ARP packets with a sender MAC address that is a multicast address

    Why it's wrong here

    ARP sender MAC addresses should be unicast addresses. A multicast MAC address in the sender field would be invalid and likely dropped by hosts. ARP poisoning typically uses the attacker's actual unicast MAC address, not a multicast address. This option is not a realistic indicator of ARP poisoning.

  • ✗

    ARP request packets with a broadcast destination MAC address

    Why it's wrong here

    ARP requests are normally broadcast to FF:FF:FF:FF:FF:FF to discover the MAC address of a target IP. This is standard ARP behavior and does not indicate poisoning. Poisoning involves unsolicited ARP replies or replies that map an IP to an incorrect MAC, not the normal broadcast requests used for resolution.

  • ✓

    Multiple ARP replies from the same MAC address claiming different IP addresses

    Why this is correct

    In ARP poisoning, an attacker sends gratuitous ARP replies to associate their MAC address with multiple IP addresses, or to impersonate the gateway. Seeing a single MAC address claiming ownership of several IPs is a strong indicator. Legitimate hosts typically have one IP per MAC address (or a few in specific configurations), so this behavior is suspicious.

  • ✗

    ARP requests sent to a unicast destination MAC address

    Why it's wrong here

    ARP requests are generally broadcast, but they can be unicast in some cases (e.g., ARP probes). However, this is not an indicator of poisoning. Poisoning relies on replies that update caches, not on the destination of requests. Unicast ARP requests are uncommon but not malicious by themselves.

  • ✓

    Gratuitous ARP replies that are not preceded by an ARP request

    Why this is correct

    Gratuitous ARP replies are sent without a corresponding request to update other hosts' ARP caches. While they can be legitimate (e.g., when a NIC comes up), a sudden increase in unsolicited ARP replies, especially mapping the gateway IP to a different MAC, is a classic sign of ARP poisoning. Attackers use this to redirect traffic through their machine.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.