Courseiva

CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography

A security analyst captures network traffic and sees multiple ARP packets with the same source MAC address but different IP addresses. Which attack is MOST likely occurring?

⚠ Common exam trap

CEH often tests whether candidates can distinguish between wireless attacks (deauth, evil twin, WPS) and Layer 2 wired attacks (ARP spoofing) — the trap is picking a wireless attack because the question mentions 'network traffic' without noting the wired ARP signature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ARP spoofing attack

ARP spoofing (also called ARP poisoning) involves an attacker sending forged ARP replies to associate their MAC address with the IP address of another host (often the gateway), causing traffic to be redirected through the attacker. Multiple ARP packets with the same source MAC but different IP addresses is the classic signature of an attacker claiming multiple IPs to intercept traffic. This enables man-in-the-middle attacks, session hijacking, and traffic sniffing on the local subnet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPS PIN attack

    Why it's wrong here

    A WPS PIN attack specifically targets the Wi-Fi Protected Setup (WPS) protocol, which is designed to simplify wireless network setup. Attackers attempt to brute-force the 8-digit WPS PIN, often exploiting a design flaw that allows the PIN to be validated in two halves. This attack aims to recover the network's pre-shared key (PSK) or passphrase, enabling unauthorized access to the Wi-Fi network, but it operates at the application layer of the WPS protocol and does not involve the manipulation or capture of Address Resolution Protocol (ARP) packets.

  • ✗

    De-authentication attack

    Why it's wrong here

    A de-authentication attack is a type of denial-of-service (DoS) attack against wireless networks, where an attacker sends forged de-authentication frames to one or more clients, or to the access point (AP) itself, impersonating the AP or the client. These frames instruct the target device to disconnect from the wireless network, effectively forcing legitimate users offline. This attack operates at the data link layer (specifically 802.11 management frames) and does not involve the Address Resolution Protocol (ARP) for its execution.

  • ✗

    Evil twin attack

    Why it's wrong here

    An evil twin attack involves setting up a rogue wireless access point (AP) that mimics a legitimate one, often by using the same Service Set Identifier (SSID) and appearing to offer a stronger signal. The attacker's goal is to trick unsuspecting users into connecting to the malicious AP, allowing the attacker to intercept their network traffic, capture credentials, or inject malware. While highly effective for man-in-the-middle (MitM) scenarios, this attack primarily operates by impersonating a Wi-Fi network and does not directly involve the manipulation or capture of Address Resolution Protocol (ARP) packets on an existing wired or wireless network segment.

  • ✓

    ARP spoofing attack

    Why this is correct

    ARP spoofing, also known as ARP poisoning, is a man-in-the-middle (MitM) attack where an attacker sends forged Address Resolution Protocol (ARP) messages over a local area network. The attacker's goal is to associate their own MAC address with the IP address of another host, such as the default gateway, or to associate the gateway's MAC address with the victim's IP. By doing so, the attacker intercepts network traffic intended for other devices, as the traffic is incorrectly routed through the attacker's machine, allowing for eavesdropping, modification, or redirection. This directly involves manipulating ARP packets to link a single MAC address to multiple IP addresses or vice-versa within the victim's ARP cache.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.