A packet capture from a branch office shows the default gateway IP mapped to a MAC address that does not belong to the router. The same suspicious MAC also answers for the DNS server IP, and gratuitous ARP replies appear every 30 seconds. Which two attacks best match this evidence? Select two.
The evidence fits ARP poisoning because an unauthorized MAC address is associating itself with trusted IP addresses such as the gateway and DNS server. Gratuitous ARP replies reinforce the cache manipulation and allow the attacker to redirect traffic at the layer 2 level. This is the classic setup for a local network spoofing attack.
Why this answer
The evidence shows the default gateway IP is mapped to a MAC address that does not belong to the router, and the same suspicious MAC also answers for the DNS server IP. This is a classic indicator of ARP spoofing or poisoning, where an attacker sends forged ARP replies to associate their MAC address with the IP addresses of critical network devices, such as the gateway and DNS server. Gratuitous ARP replies every 30 seconds further confirm an active ARP poisoning attack, as the attacker repeatedly broadcasts these unsolicited replies to maintain the poisoned ARP cache entries on victim hosts.
Exam trap
The trap here is that candidates may confuse ARP spoofing with a SYN flood or other denial-of-service attacks, failing to recognize that the specific evidence of a mismatched MAC address and gratuitous ARP replies directly points to ARP cache poisoning, not a network-level flood.