Courseiva
easyMultiple Select

ISC2 CC Practice Question: Wants to protect against man-in-the-middle…

An organization wants to protect against man-in-the-middle attacks on a switched network. Which TWO measures should be implemented? (Choose two.)

⚠ Common exam trap

Candidates often confuse Layer 2 switch hardening features. The key trap is assuming all Layer 2 controls stop MITM attacks. MITM via ARP spoofing or rogue DHCP specifically requires IP-to-MAC binding validation and untrusted DHCP filtering, not STP, MAC limiting, or traffic rate limiting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Filter untrusted DHCP server messages

Man-in-the-middle attacks on a switched network typically occur when an attacker uses a rogue DHCP server or spoofed ARP replies to redirect traffic through the attacker’s system. The two vendor-neutral protections are to filter untrusted DHCP server messages and to validate ARP messages against a trusted IP-to-MAC binding table. STP BPDU protection, MAC limiting, and broadcast/multicast rate limiting address different Layer 2 threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enforce Spanning Tree Protocol (STP) BPDU protection

    Why it's wrong here

    STP BPDU protection secures the spanning tree topology and prevents BPDU spoofing, not IP/MAC spoofing used in MITM attacks.

  • ✗

    Limit the number of MAC addresses allowed per port

    Why it's wrong here

    MAC limiting prevents MAC address table flooding, not ARP spoofing or rogue DHCP.

  • ✓

    Filter untrusted DHCP server messages

    Why this is correct

    Filtering untrusted DHCP server messages blocks rogue DHCP servers from handing out malicious IP configuration that enables MITM.

  • ✗

    Rate-limit broadcast and multicast traffic

    Why it's wrong here

    Broadcast and multicast rate limiting controls broadcast storms; it does not validate ARP or DHCP.

  • ✓

    Validate ARP requests against a trusted IP-to-MAC binding table

    Why this is correct

    Validating ARP against a trusted IP-to-MAC binding table blocks spoofed ARP replies that would redirect traffic to an attacker.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.