Courseiva

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A security analyst reviews a packet capture from a public Wi-Fi network and sees a workstation repeatedly sending gratuitous ARP replies that map the default gateway's IP address to the workstation's own MAC address. Shortly afterward, several clients on the same subnet begin sending their internet-bound traffic through that workstation. Which of the following is the MOST likely explanation for this activity?

⚠ Common exam trap

The trap here is assuming that any traffic redirection on a LAN must involve DNS or routing changes, when ARP cache manipulation alone can silently place an attacker in the path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An on-path attack using ARP cache poisoning

The spoofed gratuitous ARP replies overwrite clients' mappings of the gateway IP to the attacker's MAC, which redirects traffic through the attacker's workstation. That is the defining mechanism of an on-path attack via ARP cache poisoning. The subsequent flow of internet-bound traffic through the workstation confirms successful redirection rather than a naming, address-exhaustion, or VLAN-boundary issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A VLAN hopping attack using double-tagged 802.1Q frames

    Why it's wrong here

    VLAN hopping exploits trunk and native VLAN misconfigurations to send traffic into a different VLAN, often using double-tagged frames. Here, clients remain on the same subnet and continue communicating, but their gateway mapping is falsified. No trunk encapsulation or tag manipulation is described. The behavior is confined to Layer 2 gateway impersonation rather than crossing VLAN boundaries.

  • ✓

    An on-path attack using ARP cache poisoning

    Why this is correct

    The gratuitous ARP replies falsely bind the gateway's IP to the attacker's MAC, so victim ARP caches are overwritten and traffic is redirected through the attacker. This matches an on-path (man-in-the-middle) attack via ARP cache poisoning, which lets the attacker intercept, relay, or modify traffic. Because the scenario shows traffic flowing through the workstation after the spoofed replies, an on-path attack is the most likely explanation.

  • ✗

    A DHCP starvation attack exhausting the address pool

    Why it's wrong here

    DHCP starvation floods a server with requests using spoofed MAC addresses, exhausting leaseable addresses so new clients cannot obtain configuration. The observed gratuitous ARP replies do not request or assign IP addresses, and existing clients already have working configurations. The redirection of established traffic through a peer workstation is inconsistent with a DHCP pool exhaustion scenario.

  • ✗

    A DNS cache poisoning attack against the local resolver

    Why it's wrong here

    DNS cache poisoning corrupts name-to-IP mappings on a resolver, causing clients to reach wrong servers, but it does not rewrite MAC-to-IP bindings in ARP tables. The captured gratuitous ARP replies explicitly target the default gateway's IP, which is a Layer 2 redirection technique. DNS poisoning would not cause clients to forward their internet-bound traffic through another workstation on the same subnet.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.