easyMultiple Select
ISC2 CC Practice Question: Wants to protect against man-in-the-middle…
An organization wants to protect against man-in-the-middle attacks on a switched network. Which TWO measures should be implemented? (Choose two.)
⚠ Common exam trap
Candidates often confuse Layer 2 switch hardening features. The key trap is assuming all Layer 2 controls stop MITM attacks. MITM via ARP spoofing or rogue DHCP specifically requires IP-to-MAC binding validation and untrusted DHCP filtering, not STP, MAC limiting, or traffic rate limiting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Filter untrusted DHCP server messages
Man-in-the-middle attacks on a switched network typically occur when an attacker uses a rogue DHCP server or spoofed ARP replies to redirect traffic through the attacker’s system. The two vendor-neutral protections are to filter untrusted DHCP server messages and to validate ARP messages against a trusted IP-to-MAC binding table. STP BPDU protection, MAC limiting, and broadcast/multicast rate limiting address different Layer 2 threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enforce Spanning Tree Protocol (STP) BPDU protection
Why it's wrong here
STP BPDU protection secures the spanning tree topology and prevents BPDU spoofing, not IP/MAC spoofing used in MITM attacks.
- ✗
Limit the number of MAC addresses allowed per port
Why it's wrong here
MAC limiting prevents MAC address table flooding, not ARP spoofing or rogue DHCP.
- ✓
Filter untrusted DHCP server messages
Why this is correct
Filtering untrusted DHCP server messages blocks rogue DHCP servers from handing out malicious IP configuration that enables MITM.
- ✗
Rate-limit broadcast and multicast traffic
Why it's wrong here
Broadcast and multicast rate limiting controls broadcast storms; it does not validate ARP or DHCP.
- ✓
Validate ARP requests against a trusted IP-to-MAC binding table
Why this is correct
Validating ARP against a trusted IP-to-MAC binding table blocks spoofed ARP replies that would redirect traffic to an attacker.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
DHCP server
A DHCP server is a network device or service that automatically assigns IP addresses and other network configuration parameters to devices on a network, eliminating the need for manual configuration.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.