Courseiva
Attacks and Exploits →easyMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester is performing a network attack and wants to intercept traffic between two hosts on the same local network. Which technique should the tester use to redirect traffic through their machine?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ARP spoofing

ARP spoofing allows an attacker to associate their MAC address with the IP address of another host, intercepting traffic intended for that host.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS poisoning

    Why it's wrong here

    DNS poisoning manipulates the resolution of domain names to IP addresses by corrupting a resolver's cache or by intercepting and forging DNS responses. It operates at the application layer (or name resolution layer), so it can redirect a victim to an attacker-controlled IP for a specific hostname, but it does not alter the data-link layer MAC-IP bindings that ARP spoofing targets. Thus, it can be used in a broad phishing or redirect attack, but it is not the technique for intercepting all local traffic between hosts.

  • ✗

    LLMNR poisoning

    Why it's wrong here

    LLMNR poisoning is an attack in which the attacker listens for LLMNR name resolution queries (used when DNS fails on a local network) and responds with a spoofed answer, directing the victim to an attacker-controlled IP address. This attack exploits the name resolution process, not the ARP cache, and it only succeeds when a victim makes an unresolved hostname query. It relies on the victim's application to send traffic to the bogus IP at the network layer, whereas ARP spoofing forges replies at the data-link layer to redirect entire flows between two known hosts.

  • ✓

    ARP spoofing

    Why this is correct

    ARP spoofing is the correct technique for intercepting traffic on a local Ethernet network because ARP is stateless and lacks authentication. An attacker sends forged ARP replies to the target host and the default gateway, mapping the attacker's MAC address to the gateway's IP (and vice versa), which causes the target to send its frames to the attacker rather than directly to the gateway. This creates a man-in-the-middle position at the data-link layer, allowing the attacker to sniff, modify, or drop the traffic, and it is the foundational step for many subsequent attacks like session hijacking or credential theft.

  • ✗

    SSL stripping

    Why it's wrong here

    SSL stripping is an on-path attack that downgrades an HTTPS connection to plain HTTP by intercepting the initial HTTP request and rewriting reply URLs so the victim continues with insecure HTTP. It does not redirect traffic between hosts or alter network-layer addressing; instead, it exploits the user's failure to force TLS and the server's support of HTTP fallback. Crucially, SSL stripping requires an existing man-in-the-middle position (often achieved via ARP spoofing), so it is a consequence of a successful interception, not the method for creating that interception.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.