Courseiva
Troubleshooting →mediumMultiple Select

XK0-006 Troubleshooting Practice Question

A Linux administrator is troubleshooting a server that intermittently loses network connectivity. They suspect duplicate IP address conflicts on the local subnet. Which TWO commands can be used to detect whether another host is using the same IP address as the server? (Choose two.)

⚠ Common exam trap

The trap here is assuming that a ping sweep or ARP cache listing will reveal an IP conflict, when only active ARP probing or capturing ARP frames can expose two hosts using the same address.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

arping -D -I eth0 192.168.1.50

Duplicate IP detection requires either actively probing with ARP, as `arping -D` does, or passively observing ARP traffic for conflicting MAC-to-IP mappings, which `tcpdump -i eth0 arp` provides. Both methods operate at layer 2 where the conflict manifests. Commands that merely list hosts or interface settings cannot reveal two hosts claiming the same address.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ip neigh show

    Why it's wrong here

    `ip neigh show` displays the current ARP cache entries, mapping IP addresses to MAC addresses. While it can reveal a MAC address for a given IP, it does not actively probe for duplicates and may show stale or incomplete entries. It cannot definitively confirm a conflict because the cache might not reflect a second host using the same IP, especially if the conflict is intermittent.

  • ✓

    arping -D -I eth0 192.168.1.50

    Why this is correct

    `arping -D` sends ARP probes in duplicate address detection mode. If another host replies, a duplicate IP is present. Specifying the interface with `-I eth0` and the target IP checks that address on the local segment. This is a direct and reliable method to detect IP conflicts because ARP operates at layer 2 and will receive a response from any host claiming the same address.

  • ✗

    nmap -sn 192.168.1.0/24

    Why it's wrong here

    `nmap -sn` performs a ping sweep to discover live hosts on a subnet. It lists hosts that respond but does not associate them with MAC addresses or detect duplicates. If two hosts share an IP, the sweep would show only one entry for that IP, hiding the conflict. Therefore, it cannot reliably identify duplicate IP addresses on the local network.

  • ✗

    ethtool eth0

    Why it's wrong here

    `ethtool eth0` displays link settings such as speed, duplex, and driver information for the network interface. It operates at the physical layer and does not inspect IP addresses or ARP traffic. It cannot detect duplicate IP conflicts because it has no visibility into layer 3 addressing or ARP exchanges occurring on the subnet.

  • ✓

    tcpdump -i eth0 arp

    Why this is correct

    `tcpdump -i eth0 arp` captures ARP traffic on the interface. In a duplicate IP scenario, you would observe two different MAC addresses responding to ARP requests for the same IP, or gratuitous ARP announcements from conflicting hosts. This passive monitoring can confirm the presence of a conflict without generating additional traffic, making it a valid detection method.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.