ISC2 CC Network Security Practice Question
A security analyst detects an ARP spoofing attack on the local network. What is the primary goal of an ARP spoofing attack?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To redirect traffic to the attacker's machine for eavesdropping or modification
ARP spoofing allows an attacker to intercept traffic by associating their MAC address with the IP address of a legitimate host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To disable the switch by sending fake VLAN tags
Why it's wrong here
ARP spoofing poisons the IP-to-MAC mapping in hosts' ARP caches, redirecting traffic through the attacker for interception or modification; it never disables a switch or manipulates VLAN tags, which is VLAN hopping via 802.1Q double tagging. The option tempts because both are Layer 2 attacks, but VLAN hopping targets switch segmentation, not ARP resolution.
- ✗
To overwhelm the network with broadcast traffic
Why it's wrong here
ARP spoofing poisons the IP-to-MAC mapping so traffic is redirected through the attacker, enabling interception or man-in-the-middle manipulation. It tempts because broadcast flooding is a real attack symptom, and overwhelming the network with broadcast traffic is the goal of an ARP flooding or MAC flooding denial-of-service attack.
- ✓
To redirect traffic to the attacker's machine for eavesdropping or modification
Why this is correct
ARP spoofing forges gratuitous ARP replies that bind the gateway's IP address to the attacker's MAC address, so victims forward their frames to the attacker. The attacker then relays traffic onward while capturing credentials and session data, or alters payloads in transit, satisfying the eavesdropping and modification goal.
- ✗
To corrupt the DNS cache
Why it's wrong here
ARP spoofing corrupts the ARP cache, mapping a legitimate IP to the attacker's MAC; DNS cache poisoning is a separate attack altering name-resolution records, typically via forged responses or cache-injection flaws. The option tempts because both redirect traffic, but DNS poisoning operates at the application-layer resolver, not the link-layer ARP table.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.