Courseiva
Networking and Protocols →hardMultiple Choice

GSEC Networking and Protocols Practice Question

An analyst reviewing packet captures from a corporate network sees a workstation send an ARP request for the default gateway's IP address. Within milliseconds, two different ARP replies arrive from two different MAC addresses, and the workstation begins forwarding all off-subnet traffic to the second MAC. The analyst suspects an on-path attack. Which security control would most directly prevent this specific behavior on the local segment?

⚠ Common exam trap

The trap here is assuming that any Layer 2 hardening feature, such as 802.1X or private VLANs, will stop ARP spoofing, when only Dynamic ARP Inspection validates ARP payloads against a trusted binding table.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configuring Dynamic ARP Inspection with a DHCP snooping binding table

Dynamic ARP Inspection is the control specifically designed to stop forged ARP replies. By relying on the DHCP snooping binding table as its source of truth for which MAC legitimately owns which IP, the switch can drop any ARP packet whose sender information does not match an authorized binding. This blocks the attacker's spoofed reply before the workstation can poison its cache and redirect off-subnet traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enabling private VLAN edge isolation between access ports

    Why it's wrong here

    Private VLAN edge, also called port isolation, prevents hosts on the same switch from communicating directly with one another by forcing traffic through an uplink. It can limit lateral movement, but it does not validate ARP contents, and in many designs the attacker and victim would still share a path to the gateway. It also disrupts legitimate peer-to-peer traffic, making it a poor fit for the stated requirement.

  • ✗

    Deploying 802.1X port-based network access control on access ports

    Why it's wrong here

    802.1X authenticates devices before granting them access to the switch port, which stops unauthorized devices from connecting at all. However, once a legitimate device is authenticated and its port is authorized, it can still send forged ARP replies to other hosts. Because the attack in this scenario comes from an already-connected host, 802.1X alone does not prevent the spoofed ARP reply from being accepted.

  • ✓

    Configuring Dynamic ARP Inspection with a DHCP snooping binding table

    Why this is correct

    Dynamic ARP Inspection intercepts ARP packets on untrusted ports and compares the sender IP and MAC against the DHCP snooping binding database. A forged reply from a MAC that does not own the gateway address is dropped before it reaches the workstation, so the victim never updates its ARP cache with the attacker's address. This directly targets the gratuitous or unsolicited ARP reply used in the on-path attack.

  • ✗

    Enabling Spanning Tree Protocol on all access switches

    Why it's wrong here

    Spanning Tree Protocol prevents Layer 2 loops by blocking redundant paths between switches, but it does not validate ARP replies or bind IP addresses to MAC addresses. An attacker on the same access port can still send a forged ARP reply that the workstation accepts, because the switch simply forwards the frame. STP addresses topology loops, not ARP spoofing, so it would not stop this attack.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.