Courseiva
Security Concepts →hardMultiple Choice

200-201 Security Concepts Practice Question

During a security audit, it is discovered that an organization’s network is vulnerable to ARP spoofing attacks. Which type of attack could result from exploiting this vulnerability?

⚠ Common exam trap

200-201 often tests the distinction between ARP spoofing's direct effect (MITM) and its secondary effects (DoS, DNS poisoning) — candidates must identify the primary, canonical consequence the question is targeting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Man-in-the-middle

ARP spoofing allows an attacker to send forged ARP replies that associate the attacker's MAC address with a legitimate IP (e.g., the default gateway), causing victims to send traffic to the attacker instead of the real destination. The attacker then relays traffic between the victim and the gateway, positioning themselves in the path — a classic man-in-the-middle (MITM) attack that enables eavesdropping, session hijacking, and credential theft.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS poisoning

    Why it's wrong here

    ARP spoofing poisons the IP-to-MAC mapping, letting an attacker intercept or alter frames on the local segment. DNS poisoning requires compromising resolver records or responses, a separate mechanism. DNS poisoning would be correct had the vulnerability been an unsecured or spoofable DNS resolver.

  • ✓

    Man-in-the-middle

    Why this is correct

    ARP spoofing lets an attacker send forged ARP replies, poisoning victims' caches so traffic is redirected through the attacker's machine. Positioned between two communicating hosts, the attacker relays traffic while reading or altering it, producing a man-in-the-middle condition.

  • ✗

    Phishing

    Why it's wrong here

    Phishing relies on deceiving users into surrendering credentials or clicking malicious links; it does not require layer-2 MAC-to-IP manipulation. ARP spoofing enables on-path interception instead. Phishing would be correct had the finding been weak email filtering or absent user awareness training.

  • ✗

    DoS

    Why it's wrong here

    ARP spoofing enables a man-in-the-middle position, letting an attacker redirect or blackhole traffic, which can produce a denial-of-service condition; but DoS is a consequence, not the attack class the vulnerability itself defines. DoS is the answer when the stem asks what impact results, not what ARP spoofing fundamentally is.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.