GSEC Networking and Protocols Practice Question
A security analyst is reviewing packet captures from a corporate network and notices that several internal hosts are receiving unsolicited ARP replies claiming that the default gateway's IP address maps to a MAC address belonging to an unknown device. The analyst confirms the legitimate gateway MAC is different. Which type of attack is most likely occurring?
⚠ Common exam trap
Watch out — candidates often confuse ARP cache poisoning with MAC flooding, but MAC flooding targets switch CAM tables, not host ARP caches, and does not produce forged gateway mappings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ARP cache poisoning
Unsolicited ARP replies that incorrectly map the default gateway's IP to an attacker-controlled MAC address are the hallmark of ARP cache poisoning. This attack poisons the ARP cache of hosts, redirecting their traffic through the attacker for interception or disruption. The mismatch between the legitimate gateway MAC and the claimed MAC confirms the malicious manipulation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ARP cache poisoning
Why this is correct
ARP cache poisoning involves sending forged ARP replies to associate an attacker's MAC address with a legitimate IP, such as the default gateway. This allows the attacker to intercept or redirect traffic. In this scenario, the unsolicited replies with a mismatched MAC for the gateway IP are a classic indicator of ARP spoofing, enabling man-in-the-middle or denial-of-service conditions on the LAN.
- ✗
VLAN hopping
Why it's wrong here
VLAN hopping allows an attacker to send traffic to a different VLAN by exploiting switch trunking or double-tagging. It does not involve ARP replies or gateway MAC address manipulation. The evidence here is ARP-based deception, not VLAN segmentation bypass. Therefore, VLAN hopping is unrelated to the observed unsolicited ARP replies and MAC mismatch.
- ✗
DHCP starvation
Why it's wrong here
DHCP starvation exhausts the DHCP server's address pool by flooding it with requests using spoofed MAC addresses, preventing legitimate clients from obtaining IP configurations. It does not involve unsolicited ARP replies or gateway MAC mismatches. The observed traffic is specifically ARP-related and targets the gateway mapping, so DHCP starvation is not the correct classification.
- ✗
MAC flooding
Why it's wrong here
MAC flooding overwhelms a switch's CAM table with numerous fake source MAC addresses, causing the switch to fail open and broadcast traffic. While it can lead to traffic interception, it does not generate unsolicited ARP replies with incorrect IP-to-MAC mappings. The scenario explicitly describes ARP replies claiming the gateway IP maps to an unknown MAC, which is not a characteristic of MAC flooding.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.