Courseiva
Question 998 of 1,013
Threats, Vulnerabilities, and MitigationshardMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

Exhibit

Host 192.0.2.45 arp -a
Internet Address      Physical Address      Type
192.0.2.1             00-50-56-a1-b2-c3     dynamic
192.0.2.1             00-50-56-a1-b2-c4     dynamic

Packet capture:
10:14:02 ARP Reply: 192.0.2.1 is-at 00:50:56:a1:b2:c4
10:14:03 ARP Reply: 192.0.2.1 is-at 00:50:56:a1:b2:c4
10:14:05 Gateway traffic is briefly forwarded to 192.0.2.200

Switch CAM table:
Gi1/0/7   00:50:56:a1:b2:c4
Gi1/0/24  00:50:56:a1:b2:c4

Based on the exhibit, which attack is most likely occurring on the local network?

⚠ Common exam trap

Many candidates confuse ARP spoofing with DNS cache poisoning because both involve 'poisoning' a cache, but ARP operates at Layer 2 (MAC addresses) while DNS operates at Layer 7 (domain name resolution).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

ARP spoofing

ARP spoofing is the most likely attack because the exhibit shows an attacker sending forged ARP replies to associate the attacker's MAC address with the IP address of the default gateway. This poisons the ARP cache of the victim, causing all traffic destined for the gateway to be sent to the attacker instead, enabling man-in-the-middle interception.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • DNS cache poisoning

    Why it's wrong here

    DNS cache poisoning corrupts the cached records of a DNS resolver so that a legitimate domain name resolves to an attacker-controlled IP address. This manipulation occurs at the application layer (DNS over UDP/TCP), not at the Ethernet/data-link layer where ARP operates. The exhibit shows repeated ARP replies claiming the gateway IP belongs to a different MAC address, which is a Layer 2 attack; DNS poisoning cannot alter MAC-to-IP bindings on a local subnet.

  • ARP spoofing

    Why this is correct

    The host receives repeated ARP replies claiming the gateway IP belongs to a different MAC address, and the same MAC appears on multiple switch ports. That combination indicates ARP spoofing or poisoning, which can redirect traffic through an attacker for interception or disruption. The brief forwarding to another IP is consistent with a man-in-the-middle attempt built on forged ARP replies.

  • Replay attack

    Why it's wrong here

    A replay attack involves capturing a valid, authenticated network exchange and retransmitting it later to trick the receiver into granting access or performing an action. The retransmitted packets are exact copies of the original, so they do not modify ARP mappings or introduce a new MAC address for a gateway. ARP spoofing, by contrast, forges unsolicited ARP replies to actively hijack the switch's MAC address table and redirect traffic, which is a real-time man-in-the-middle technique, not a replay.

  • Amplification denial-of-service

    Why it's wrong here

    Amplification denial-of-service attacks exploit protocols like DNS or NTP where a small query triggers a large response, then flood the victim with high-volume traffic from many spoofed sources. This is a volumetric attack aimed at exhausting bandwidth or resources, not at manipulating local network addressing. The exhibit shows a single node receiving repeated ARP replies and forwarding traffic to another IP, which is targeted and low-volume—consistent with ARP spoofing, not an amplification echo storm.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Based on the exhibit, what network attack is most likely occurring on the office LAN?

medium
  • A.ARP poisoning, because a rogue system is sending false layer 2 address mappings.
  • B.Replay attack, because the same ARP reply appears multiple times.
  • C.Denial of service, because users notice certificate warnings.
  • D.DNS poisoning, because the users cannot reach internal sites cleanly.

Why A: ARP poisoning is the correct answer because the exhibit shows a rogue system sending unsolicited ARP replies that map the gateway's IP address to the attacker's MAC address. This causes traffic destined for the gateway to be redirected to the attacker, enabling man-in-the-middle interception. The attack exploits the lack of authentication in ARP, allowing false layer 2 address mappings to corrupt the ARP cache of other hosts on the LAN.

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.