GSEC Networking and Protocols Practice Question
An analyst reviewing packet captures from a corporate network sees a workstation send an ARP request for the default gateway's IP address. Within milliseconds, two different ARP replies arrive from two different MAC addresses, and the workstation begins forwarding all off-subnet traffic to the second MAC. The analyst suspects an on-path attack. Which security control would most directly prevent this specific behavior on the local segment?
⚠ Common exam trap
The trap here is assuming that any Layer 2 hardening feature, such as 802.1X or private VLANs, will stop ARP spoofing, when only Dynamic ARP Inspection validates ARP payloads against a trusted binding table.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configuring Dynamic ARP Inspection with a DHCP snooping binding table
Dynamic ARP Inspection is the control specifically designed to stop forged ARP replies. By relying on the DHCP snooping binding table as its source of truth for which MAC legitimately owns which IP, the switch can drop any ARP packet whose sender information does not match an authorized binding. This blocks the attacker's spoofed reply before the workstation can poison its cache and redirect off-subnet traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enabling private VLAN edge isolation between access ports
Why it's wrong here
Private VLAN edge, also called port isolation, prevents hosts on the same switch from communicating directly with one another by forcing traffic through an uplink. It can limit lateral movement, but it does not validate ARP contents, and in many designs the attacker and victim would still share a path to the gateway. It also disrupts legitimate peer-to-peer traffic, making it a poor fit for the stated requirement.
- ✗
Deploying 802.1X port-based network access control on access ports
Why it's wrong here
802.1X authenticates devices before granting them access to the switch port, which stops unauthorized devices from connecting at all. However, once a legitimate device is authenticated and its port is authorized, it can still send forged ARP replies to other hosts. Because the attack in this scenario comes from an already-connected host, 802.1X alone does not prevent the spoofed ARP reply from being accepted.
- ✓
Configuring Dynamic ARP Inspection with a DHCP snooping binding table
Why this is correct
Dynamic ARP Inspection intercepts ARP packets on untrusted ports and compares the sender IP and MAC against the DHCP snooping binding database. A forged reply from a MAC that does not own the gateway address is dropped before it reaches the workstation, so the victim never updates its ARP cache with the attacker's address. This directly targets the gratuitous or unsolicited ARP reply used in the on-path attack.
- ✗
Enabling Spanning Tree Protocol on all access switches
Why it's wrong here
Spanning Tree Protocol prevents Layer 2 loops by blocking redundant paths between switches, but it does not validate ARP replies or bind IP addresses to MAC addresses. An attacker on the same access port can still send a forged ARP reply that the workstation accepts, because the switch simply forwards the frame. STP addresses topology loops, not ARP spoofing, so it would not stop this attack.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.