Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

During a penetration test, a security analyst captures network traffic and observes a series of ARP replies without corresponding ARP requests. An internal host's IP address is suddenly associated with two different MAC addresses. Which attack is MOST likely occurring?

⚠ Common exam trap

The trap is that candidates often confuse ARP poisoning with MAC flooding because both involve MAC addresses. However, MAC flooding overwhelms the switch's CAM table with many fake MAC addresses, causing the switch to fail open and broadcast traffic. In contrast, ARP poisoning targets host ARP caches by sending forged ARP replies mapping a single IP to multiple MACs, enabling MITM attacks. The absence of ARP requests and the IP-to-dual-MAC mapping points directly to ARP poisoning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ARP poisoning

D is correct because ARP poisoning (also known as ARP spoofing) involves sending forged ARP replies to associate a target IP address with an attacker's MAC address, allowing man-in-the-middle attacks. The observation of unsolicited ARP replies (gratuitous ARPs) that map one IP to two different MAC addresses is the classic signature of an ongoing ARP poisoning attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Session hijacking

    Why it's wrong here

    ARP replies lacking matching requests, with one IP mapped to two MAC addresses, indicate ARP cache poisoning (spoofing) enabling man-in-the-middle interception. Session hijacking targets an established TCP or web session by stealing tokens or sequence numbers, not by forging ARP mappings; it would be the answer if a valid session identifier were captured and reused.

  • ✗

    MAC flooding

    Why it's wrong here

    MAC flooding exhausts a switch's CAM table, forcing it to broadcast frames, but does not create duplicate IP-to-MAC bindings or unsolicited ARP replies. It suits overwhelming switch memory to enable sniffing, not the ARP cache poisoning evidenced here.

  • ✗

    DNS spoofing

    Why it's wrong here

    DNS spoofing forges name-resolution replies, altering hostname-to-IP mappings, not IP-to-MAC associations. It is tempting because both poison cached records, but DNS spoofing suits redirecting users to malicious sites, whereas duplicate MAC bindings indicate ARP cache poisoning.

  • ✓

    ARP poisoning

    Why this is correct

    Unsolicited ARP replies that remap an internal IP to a second MAC address indicate forged ARP responses, letting the attacker intercept traffic. This satisfies the stem's evidence: gratuitous replies without matching requests plus duplicate IP-to-MAC associations are the signature of ARP poisoning.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.