PT0-002 Attacks and Exploits Practice Question
A penetration tester is performing an ARP spoofing attack using Bettercap to intercept traffic between a client and the gateway. What is the primary goal of this attack?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To intercept and manipulate network traffic
ARP spoofing allows the attacker to intercept traffic, enabling man-in-the-middle attacks to capture or modify data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To perform a denial-of-service attack
Why it's wrong here
ARP spoofing can certainly be weaponized to deny service: if the attacker maps the gateway IP to a non-existent or unreachable MAC, the victim's outbound frames are dropped, severing connectivity. However, that outcome is an extreme side effect of cache poisoning, not its defining purpose. The attack's core, as a penetration testing technique, is establishing an interception position between victim and gateway so traffic can be captured or altered, not merely disrupted. Thus, while DoS is a possible consequence, it is not the primary intent.
- ✗
To bypass firewall rules
Why it's wrong here
Firewall rules are evaluated in the network stack when packets traverse the firewall's interfaces; ARP spoofing operates on the local broadcast domain at Layer 2, silently redirecting frames by lying about MAC-to-IP mappings. Because ARP is not a routable protocol and is confined to a single subnet, the attacker cannot magically "skip" a firewall. In fact, if the victim sends traffic to a poisoned gateway MAC, that traffic still travels through the same physical network path; the attacker simply needs to forward it onward. The goal is not to evade filtering but to insert an unseen middlebox, so labeling it a firewall bypass mischaracterizes both the mechanism and the objective.
- ✗
To crack wireless passwords
Why it's wrong here
Wi-Fi password cracking is centered on the pre-shared key (PSK) and the WPA2/WPA3 4-way handshake, which occur between the supplicant and access point. That process is authenticated and encrypted rather than ARP-based, and ARP frames exist only after successful association on 802.11. ARP spoofing targets hosts on an already-connected Ethernet-like LAN to intercept their traffic, whereas wireless cracking targets the link-layer authentication material itself. Therefore, invoking ARP spoofing to guess PSKs confuses a post-authenticated interception technique with a pre-authentication credential attack.
- ✓
To intercept and manipulate network traffic
Why this is correct
ARP spoofing is the quintessential man-in-the-middle technique: the tester crafts forged ARP replies that poison the target's ARP cache, mapping their MAC address to the default gateway's IP. All outbound traffic is then forwarded to the attacker's machine, which can passively capture it (e.g., creds, sessions) or actively manipulate contents before relaying to the true gateway. This enables rogue access, session hijacking, and traffic injection while remaining invisible to the victim. Because passive sniffing on switched networks is normally nullified by MAC tables, ARP poisoning re-opens that interception path.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.