SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A security analyst reviews a packet capture from a public Wi-Fi network and sees a workstation repeatedly sending gratuitous ARP replies that map the default gateway's IP address to the workstation's own MAC address. Shortly afterward, several clients on the same subnet begin sending their internet-bound traffic through that workstation. Which of the following is the MOST likely explanation for this activity?
⚠ Common exam trap
The trap here is assuming that any traffic redirection on a LAN must involve DNS or routing changes, when ARP cache manipulation alone can silently place an attacker in the path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An on-path attack using ARP cache poisoning
The spoofed gratuitous ARP replies overwrite clients' mappings of the gateway IP to the attacker's MAC, which redirects traffic through the attacker's workstation. That is the defining mechanism of an on-path attack via ARP cache poisoning. The subsequent flow of internet-bound traffic through the workstation confirms successful redirection rather than a naming, address-exhaustion, or VLAN-boundary issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A VLAN hopping attack using double-tagged 802.1Q frames
Why it's wrong here
VLAN hopping exploits trunk and native VLAN misconfigurations to send traffic into a different VLAN, often using double-tagged frames. Here, clients remain on the same subnet and continue communicating, but their gateway mapping is falsified. No trunk encapsulation or tag manipulation is described. The behavior is confined to Layer 2 gateway impersonation rather than crossing VLAN boundaries.
- ✓
An on-path attack using ARP cache poisoning
Why this is correct
The gratuitous ARP replies falsely bind the gateway's IP to the attacker's MAC, so victim ARP caches are overwritten and traffic is redirected through the attacker. This matches an on-path (man-in-the-middle) attack via ARP cache poisoning, which lets the attacker intercept, relay, or modify traffic. Because the scenario shows traffic flowing through the workstation after the spoofed replies, an on-path attack is the most likely explanation.
- ✗
A DHCP starvation attack exhausting the address pool
Why it's wrong here
DHCP starvation floods a server with requests using spoofed MAC addresses, exhausting leaseable addresses so new clients cannot obtain configuration. The observed gratuitous ARP replies do not request or assign IP addresses, and existing clients already have working configurations. The redirection of established traffic through a peer workstation is inconsistent with a DHCP pool exhaustion scenario.
- ✗
A DNS cache poisoning attack against the local resolver
Why it's wrong here
DNS cache poisoning corrupts name-to-IP mappings on a resolver, causing clients to reach wrong servers, but it does not rewrite MAC-to-IP bindings in ARP tables. The captured gratuitous ARP replies explicitly target the default gateway's IP, which is a Layer 2 redirection technique. DNS poisoning would not cause clients to forward their internet-bound traffic through another workstation on the same subnet.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Physical Security Attacks
Key term
Subnet
A subnet is a logical subdivision of an IP network, created by partitioning a larger network address space using subnet masks.
Key term
VLAN
A VLAN (Virtual Local Area Network) is a logical grouping of network devices that behave as if they are on the same physical network segment, regardless of their actual physical location.
About these practice questions
This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.