200-201 Security Concepts Practice Question
During a security audit, it is discovered that an organization’s network is vulnerable to ARP spoofing attacks. Which type of attack could result from exploiting this vulnerability?
⚠ Common exam trap
200-201 often tests the distinction between ARP spoofing's direct effect (MITM) and its secondary effects (DoS, DNS poisoning) — candidates must identify the primary, canonical consequence the question is targeting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Man-in-the-middle
ARP spoofing allows an attacker to send forged ARP replies that associate the attacker's MAC address with a legitimate IP (e.g., the default gateway), causing victims to send traffic to the attacker instead of the real destination. The attacker then relays traffic between the victim and the gateway, positioning themselves in the path — a classic man-in-the-middle (MITM) attack that enables eavesdropping, session hijacking, and credential theft.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS poisoning
Why it's wrong here
ARP spoofing poisons the IP-to-MAC mapping, letting an attacker intercept or alter frames on the local segment. DNS poisoning requires compromising resolver records or responses, a separate mechanism. DNS poisoning would be correct had the vulnerability been an unsecured or spoofable DNS resolver.
- ✓
Man-in-the-middle
Why this is correct
ARP spoofing lets an attacker send forged ARP replies, poisoning victims' caches so traffic is redirected through the attacker's machine. Positioned between two communicating hosts, the attacker relays traffic while reading or altering it, producing a man-in-the-middle condition.
- ✗
Phishing
Why it's wrong here
Phishing relies on deceiving users into surrendering credentials or clicking malicious links; it does not require layer-2 MAC-to-IP manipulation. ARP spoofing enables on-path interception instead. Phishing would be correct had the finding been weak email filtering or absent user awareness training.
- ✗
DoS
Why it's wrong here
ARP spoofing enables a man-in-the-middle position, letting an attacker redirect or blackhole traffic, which can produce a denial-of-service condition; but DoS is a consequence, not the attack class the vulnerability itself defines. DoS is the answer when the stem asks what impact results, not what ARP spoofing fundamentally is.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.