CEH Practice Question: Malware, Social Engineering and Network Attacks
During a penetration test, a security analyst captures network traffic and observes a series of ARP replies without corresponding ARP requests. An internal host's IP address is suddenly associated with two different MAC addresses. Which attack is MOST likely occurring?
⚠ Common exam trap
The trap is that candidates often confuse ARP poisoning with MAC flooding because both involve MAC addresses. However, MAC flooding overwhelms the switch's CAM table with many fake MAC addresses, causing the switch to fail open and broadcast traffic. In contrast, ARP poisoning targets host ARP caches by sending forged ARP replies mapping a single IP to multiple MACs, enabling MITM attacks. The absence of ARP requests and the IP-to-dual-MAC mapping points directly to ARP poisoning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ARP poisoning
D is correct because ARP poisoning (also known as ARP spoofing) involves sending forged ARP replies to associate a target IP address with an attacker's MAC address, allowing man-in-the-middle attacks. The observation of unsolicited ARP replies (gratuitous ARPs) that map one IP to two different MAC addresses is the classic signature of an ongoing ARP poisoning attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Session hijacking
Why it's wrong here
ARP replies lacking matching requests, with one IP mapped to two MAC addresses, indicate ARP cache poisoning (spoofing) enabling man-in-the-middle interception. Session hijacking targets an established TCP or web session by stealing tokens or sequence numbers, not by forging ARP mappings; it would be the answer if a valid session identifier were captured and reused.
- ✗
MAC flooding
Why it's wrong here
MAC flooding exhausts a switch's CAM table, forcing it to broadcast frames, but does not create duplicate IP-to-MAC bindings or unsolicited ARP replies. It suits overwhelming switch memory to enable sniffing, not the ARP cache poisoning evidenced here.
- ✗
DNS spoofing
Why it's wrong here
DNS spoofing forges name-resolution replies, altering hostname-to-IP mappings, not IP-to-MAC associations. It is tempting because both poison cached records, but DNS spoofing suits redirecting users to malicious sites, whereas duplicate MAC bindings indicate ARP cache poisoning.
- ✓
ARP poisoning
Why this is correct
Unsolicited ARP replies that remap an internal IP to a second MAC address indicate forged ARP responses, letting the attacker intercept traffic. This satisfies the stem's evidence: gratuitous replies without matching requests plus duplicate IP-to-MAC associations are the signature of ARP poisoning.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.