Courseiva
Networking and Protocols →mediumMultiple Choice

GSEC Networking and Protocols Practice Question

A security analyst is reviewing packet captures from a corporate network and notices that several internal hosts are receiving unsolicited ARP replies claiming that the default gateway's IP address maps to a MAC address belonging to an unknown device. The analyst confirms the legitimate gateway MAC is different. Which type of attack is most likely occurring?

⚠ Common exam trap

Watch out — candidates often confuse ARP cache poisoning with MAC flooding, but MAC flooding targets switch CAM tables, not host ARP caches, and does not produce forged gateway mappings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ARP cache poisoning

Unsolicited ARP replies that incorrectly map the default gateway's IP to an attacker-controlled MAC address are the hallmark of ARP cache poisoning. This attack poisons the ARP cache of hosts, redirecting their traffic through the attacker for interception or disruption. The mismatch between the legitimate gateway MAC and the claimed MAC confirms the malicious manipulation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ARP cache poisoning

    Why this is correct

    ARP cache poisoning involves sending forged ARP replies to associate an attacker's MAC address with a legitimate IP, such as the default gateway. This allows the attacker to intercept or redirect traffic. In this scenario, the unsolicited replies with a mismatched MAC for the gateway IP are a classic indicator of ARP spoofing, enabling man-in-the-middle or denial-of-service conditions on the LAN.

  • ✗

    VLAN hopping

    Why it's wrong here

    VLAN hopping allows an attacker to send traffic to a different VLAN by exploiting switch trunking or double-tagging. It does not involve ARP replies or gateway MAC address manipulation. The evidence here is ARP-based deception, not VLAN segmentation bypass. Therefore, VLAN hopping is unrelated to the observed unsolicited ARP replies and MAC mismatch.

  • ✗

    DHCP starvation

    Why it's wrong here

    DHCP starvation exhausts the DHCP server's address pool by flooding it with requests using spoofed MAC addresses, preventing legitimate clients from obtaining IP configurations. It does not involve unsolicited ARP replies or gateway MAC mismatches. The observed traffic is specifically ARP-related and targets the gateway mapping, so DHCP starvation is not the correct classification.

  • ✗

    MAC flooding

    Why it's wrong here

    MAC flooding overwhelms a switch's CAM table with numerous fake source MAC addresses, causing the switch to fail open and broadcast traffic. While it can lead to traffic interception, it does not generate unsolicited ARP replies with incorrect IP-to-MAC mappings. The scenario explicitly describes ARP replies claiming the gateway IP maps to an unknown MAC, which is not a characteristic of MAC flooding.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.