mediumMultiple Choice
PT0-002 Practice Question: During a penetration test, a tester needs to…
During a penetration test, a tester needs to perform a man-in-the-middle (MITM) attack on a local network to capture credentials. Which tool should the tester use to ARP spoof and intercept traffic?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ettercap
Ettercap is a comprehensive MITM tool that supports ARP spoofing, sniffing, and injection. Wireshark is for packet analysis, not active spoofing. TCPDump is for packet capture only. Nmap can be used for discovery but not MITM.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wireshark
Why it's wrong here
Wireshark is a passive packet capture and protocol analyzer, not an active MITM tool. It can intercept and decode traffic already delivered to the host's NIC, but it cannot inject or forge packets to redirect traffic. Performing ARP poisoning requires actively sending spoofed ARP replies, which Wireshark does not do.
- ✗
Nmap
Why it's wrong here
Nmap is a network scanning and enumeration utility used for host discovery, port scanning, and service detection. While it can perform ARP-based host discovery on a local network, that merely identifies hosts; it does not forge ARP replies to reroute traffic. Nmap lacks the packet injection and forwarding mechanisms needed to establish an active MITM position.
- ✗
TCPDump
Why it's wrong here
TCPDump is a command-line packet capture tool built on libpcap, operating passively like Wireshark. It can capture packets on an interface but has no built-in capability to craft or send ARP spoofing packets. An attacker might use TCPDump after a MITM is established to sniff the redirected traffic, but it cannot initiate the attack.
- ✓
Ettercap
Why this is correct
Ettercap is a dedicated MITM attack toolkit that supports active ARP poisoning, allowing the attacker to impersonate the default gateway and intercept traffic. It sends forged ARP replies to associate the target's IP with the attacker's MAC address, then forwards packets to the legitimate destination. Ettercap also includes filters, SSL stripping, and password sniffing, making it purpose-built for this task.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.