ARP Poisoning Detection and Prevention
A security analyst discovers that users on the network are receiving ARP replies that map the default gateway IP address to an unknown MAC address. This is causing intermittent connectivity issues. Which type of attack is occurring, and what security feature should be implemented to prevent it?
Quick Answer
The giveaway here is the mismatch between a known, correct IP address and an unexpected MAC address showing up in ARP replies - that's the defining signature of ARP poisoning, where an attacker forges replies to convince hosts that the attacker's own MAC address belongs to the default gateway. Once devices update their ARP caches with that false mapping, their traffic destined for the gateway actually flows through the attacker first, which explains both the interception risk and the intermittent connectivity problems described, since the attacker's machine isn't a real router and won't forward traffic reliably. Dynamic ARP Inspection stops this by refusing to simply trust ARP traffic at face value: it checks every ARP reply against a trusted IP-to-MAC binding table, typically built from DHCP snooping records, and drops any reply whose mapping doesn't match what's already known to be legitimate. This is different from just enabling DHCP snooping alone, which protects DHCP messages specifically but does nothing to validate ARP traffic on its own. Whenever a scenario describes the gateway's IP address suddenly resolving to the wrong MAC address alongside connectivity disruption, think ARP poisoning, and remember that DAI is the Layer 2 control built specifically to validate ARP messages against a trusted binding table.
⚠ Common exam trap
CompTIA often tests the distinction between Layer 2 attacks (ARP poisoning, MAC flooding) and Layer 3/4 attacks (DHCP starvation, DNS poisoning), so candidates mistakenly choose DHCP starvation or DNS poisoning because they involve 'spoofing' or 'poisoning' without recognizing that the symptom—ARP replies mapping the gateway IP to an unknown MAC—is a direct indicator of ARP manipulation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ARP poisoning; Dynamic ARP Inspection (DAI)
This attack is ARP poisoning (also called ARP spoofing), where an attacker sends forged ARP replies to associate the default gateway's IP address with the attacker's MAC address. This allows the attacker to intercept, modify, or drop traffic intended for the gateway. Dynamic ARP Inspection (DAI) prevents this by validating ARP packets against a trusted DHCP snooping binding table, dropping any ARP reply that contains an IP-to-MAC mapping not present in the table.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MAC flooding; port security
Why it's wrong here
MAC flooding overwhelms the switch MAC table but does not involve forging ARP replies.
When this WOULD be correct
A question describing a switch receiving thousands of fake MAC addresses, causing it to fail open and flood traffic to all ports, where the solution is port security to limit MAC addresses per port.
- ✓
ARP poisoning; Dynamic ARP Inspection (DAI)
Why this is correct
DAI trusts only ARP responses that match a valid IP-to-MAC binding, preventing ARP spoofing.
- ✗
DHCP starvation; DHCP snooping
Why it's wrong here
DHCP starvation exhausts the DHCP server's address pool; DHCP snooping prevents rogue DHCP servers, not ARP attacks.
When this WOULD be correct
A question describing users unable to obtain IP addresses due to a rogue DHCP server exhausting the address pool, asking which attack and which mitigation (e.g., DHCP snooping) would be correct.
- ✗
DNS poisoning; DNSSEC
Why it's wrong here
DNS poisoning targets the DNS cache, not ARP messages.
When this WOULD be correct
This option would be correct if the question described users being redirected to malicious websites despite typing correct URLs, or if it mentioned DNS cache poisoning causing domain name resolution to point to a rogue server.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓ARP poisoning; Dynamic ARP Inspection (DAI)Correct answer▾
Why this is correct
DAI trusts only ARP responses that match a valid IP-to-MAC binding, preventing ARP spoofing.
✗MAC flooding; port securityWrong answer — click to see why▾
Why this is wrong here
The question describes ARP replies mapping the default gateway IP to an unknown MAC, which is ARP poisoning, not MAC flooding. MAC flooding overwhelms a switch's MAC table to force fail-open mode, causing frames to flood, but does not involve spoofing ARP replies.
★ When this WOULD be the correct answer
A question describing a switch receiving thousands of fake MAC addresses, causing it to fail open and flood traffic to all ports, where the solution is port security to limit MAC addresses per port.
Why candidates choose this
Candidates confuse ARP poisoning with MAC flooding because both involve MAC addresses and network attacks, and port security is a common security feature, leading to a mistaken association.
✗DHCP starvation; DHCP snoopingWrong answer — click to see why▾
Why this is wrong here
The question describes ARP replies mapping the default gateway IP to an unknown MAC, which is ARP poisoning, not DHCP starvation. DHCP starvation exhausts IP addresses, not ARP mappings.
★ When this WOULD be the correct answer
A question describing users unable to obtain IP addresses due to a rogue DHCP server exhausting the address pool, asking which attack and which mitigation (e.g., DHCP snooping) would be correct.
Why candidates choose this
Candidates may confuse network-layer attacks involving spoofing or exhaustion, and DHCP starvation is a common attack that also uses spoofed messages, leading to misidentification.
✗DNS poisoning; DNSSECWrong answer — click to see why▾
Why this is wrong here
DNS poisoning manipulates DNS records, not ARP tables. The question describes ARP replies mapping a gateway IP to a wrong MAC, which is ARP poisoning, not DNS poisoning.
★ When this WOULD be the correct answer
This option would be correct if the question described users being redirected to malicious websites despite typing correct URLs, or if it mentioned DNS cache poisoning causing domain name resolution to point to a rogue server.
Why candidates choose this
Candidates may confuse network-layer attacks (ARP) with application-layer attacks (DNS), both involving mapping IPs to wrong destinations, leading them to select DNS poisoning when the symptoms involve IP-to-MAC mapping.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Network Device Hardening
Key term
DHCP snooping
DHCP snooping is a network security feature that filters untrusted DHCP messages to prevent rogue DHCP servers from giving out false IP addresses.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every N10-009 question from scratch — 464 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on N10-009
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A network security analyst notices high CPU utilization on the core switch and detects a large volume of ARP replies from a single IP address that claims to be the default gateway for all local subnets. Which type of attack is MOST likely occurring?
medium- ✓ A.ARP poisoning
- B.DHCP starvation
- C.MAC flooding
- D.DNS amplification
Why A: The attack described is ARP poisoning (also known as ARP spoofing), where an attacker sends forged ARP replies to associate their MAC address with the IP address of the default gateway. This causes all traffic destined for other subnets to be redirected to the attacker's machine, leading to high CPU utilization on the switch as it processes the flood of ARP packets and forwards the intercepted traffic.
Variation 2. A security analyst discovers that an unauthorized device is sending forged ARP replies to poison the ARP caches of other devices on the network. Which security feature should be implemented on the switches to prevent this?
medium- A.Port security
- B.DHCP snooping
- ✓ C.Dynamic ARP Inspection
- D.STP BPDU guard
Why C: Dynamic ARP Inspection (DAI) validates ARP packets on a per-interface basis by intercepting all ARP requests and replies and verifying that they match entries in the DHCP snooping binding table. If an ARP reply contains a forged IP-to-MAC mapping, DAI drops the packet, preventing ARP cache poisoning. This directly stops the described attack where an unauthorized device sends forged ARP replies.
Variation 3. A security analyst discovers that an unauthorized device is sending forged ARP replies, causing other devices to map the default gateway IP address to the attacker's MAC address. Which security feature should be implemented on the switches to prevent this attack?
medium- A.Port security
- B.DHCP snooping
- ✓ C.Dynamic ARP Inspection
- D.BPDU guard
Why C: Dynamic ARP Inspection (DAI) is the correct choice because it validates ARP packets on a per-port basis, ensuring that only legitimate ARP replies with correct IP-to-MAC bindings are forwarded. DAI uses a DHCP snooping binding table (or static ARP ACLs) to intercept and verify ARP packets, dropping forged replies that attempt to poison the ARP cache of other devices.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.