PT0-002 Attacks and Exploits Practice Question
A penetration tester is performing a network attack and wants to intercept traffic between two hosts on the same local network. Which technique should the tester use to redirect traffic through their machine?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ARP spoofing
ARP spoofing allows an attacker to associate their MAC address with the IP address of another host, intercepting traffic intended for that host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS poisoning
Why it's wrong here
DNS poisoning manipulates the resolution of domain names to IP addresses by corrupting a resolver's cache or by intercepting and forging DNS responses. It operates at the application layer (or name resolution layer), so it can redirect a victim to an attacker-controlled IP for a specific hostname, but it does not alter the data-link layer MAC-IP bindings that ARP spoofing targets. Thus, it can be used in a broad phishing or redirect attack, but it is not the technique for intercepting all local traffic between hosts.
- ✗
LLMNR poisoning
Why it's wrong here
LLMNR poisoning is an attack in which the attacker listens for LLMNR name resolution queries (used when DNS fails on a local network) and responds with a spoofed answer, directing the victim to an attacker-controlled IP address. This attack exploits the name resolution process, not the ARP cache, and it only succeeds when a victim makes an unresolved hostname query. It relies on the victim's application to send traffic to the bogus IP at the network layer, whereas ARP spoofing forges replies at the data-link layer to redirect entire flows between two known hosts.
- ✓
ARP spoofing
Why this is correct
ARP spoofing is the correct technique for intercepting traffic on a local Ethernet network because ARP is stateless and lacks authentication. An attacker sends forged ARP replies to the target host and the default gateway, mapping the attacker's MAC address to the gateway's IP (and vice versa), which causes the target to send its frames to the attacker rather than directly to the gateway. This creates a man-in-the-middle position at the data-link layer, allowing the attacker to sniff, modify, or drop the traffic, and it is the foundational step for many subsequent attacks like session hijacking or credential theft.
- ✗
SSL stripping
Why it's wrong here
SSL stripping is an on-path attack that downgrades an HTTPS connection to plain HTTP by intercepting the initial HTTP request and rewriting reply URLs so the victim continues with insecure HTTP. It does not redirect traffic between hosts or alter network-layer addressing; instead, it exploits the user's failure to force TLS and the server's support of HTTP fallback. Crucially, SSL stripping requires an existing man-in-the-middle position (often achieved via ARP spoofing), so it is a consequence of a successful interception, not the method for creating that interception.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.