SSCP Network and Communications Security Practice Question
A security analyst notices an unusual number of ARP replies on the network where one MAC address is claiming to be multiple IP addresses. Which type of attack is most likely occurring?
⚠ Common exam trap
SSCP often tests the confusion between ARP spoofing and other network attacks like DNS poisoning or DHCP starvation, where candidates might focus on the 'multiple IP addresses' aspect and incorrectly choose DHCP starvation, which also involves multiple IPs but through a different mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ARP spoofing
ARP spoofing (or ARP poisoning) involves an attacker sending forged ARP replies to associate their MAC address with multiple IP addresses, causing traffic intended for those IPs to be redirected to the attacker. This matches the scenario where one MAC address claims to be multiple IP addresses. The goal is often to intercept, modify, or block network traffic (man-in-the-middle).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ARP spoofing
Why this is correct
ARP spoofing involves an attacker sending forged ARP replies that bind one MAC address to multiple IP addresses, poisoning neighbours' ARP caches so traffic is redirected to the attacker. This matches the observed pattern of conflicting ARP mappings.
- ✗
SYN flood
Why it's wrong here
A SYN flood exhausts TCP connection state by sending many half-open SYN packets; it never sends ARP replies. It would be correct if the symptom were a service refusing new connections, whereas one MAC claiming multiple IP addresses indicates ARP cache poisoning via forged replies.
- ✗
DNS poisoning
Why it's wrong here
DNS poisoning corrupts name-resolution records, redirecting hostnames to attacker-controlled IPs; it operates at the DNS layer, not by broadcasting ARP replies. It would fit if users were reaching fraudulent websites, but the observed one-MAC-to-many-IP ARP mapping indicates ARP spoofing.
- ✗
DHCP starvation
Why it's wrong here
DHCP starvation exhausts a server's address pool by flooding DHCPDISCOVER requests with spoofed MAC addresses; it does not forge ARP replies binding one MAC to many IPs. It would be the answer if clients were failing to obtain leases, not if ARP mappings were being poisoned.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.