Courseiva

SSCP Network and Communications Security Practice Question

A security analyst notices an unusual number of ARP replies on the network where one MAC address is claiming to be multiple IP addresses. Which type of attack is most likely occurring?

⚠ Common exam trap

SSCP often tests the confusion between ARP spoofing and other network attacks like DNS poisoning or DHCP starvation, where candidates might focus on the 'multiple IP addresses' aspect and incorrectly choose DHCP starvation, which also involves multiple IPs but through a different mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ARP spoofing

ARP spoofing (or ARP poisoning) involves an attacker sending forged ARP replies to associate their MAC address with multiple IP addresses, causing traffic intended for those IPs to be redirected to the attacker. This matches the scenario where one MAC address claims to be multiple IP addresses. The goal is often to intercept, modify, or block network traffic (man-in-the-middle).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ARP spoofing

    Why this is correct

    ARP spoofing involves an attacker sending forged ARP replies that bind one MAC address to multiple IP addresses, poisoning neighbours' ARP caches so traffic is redirected to the attacker. This matches the observed pattern of conflicting ARP mappings.

  • ✗

    SYN flood

    Why it's wrong here

    A SYN flood exhausts TCP connection state by sending many half-open SYN packets; it never sends ARP replies. It would be correct if the symptom were a service refusing new connections, whereas one MAC claiming multiple IP addresses indicates ARP cache poisoning via forged replies.

  • ✗

    DNS poisoning

    Why it's wrong here

    DNS poisoning corrupts name-resolution records, redirecting hostnames to attacker-controlled IPs; it operates at the DNS layer, not by broadcasting ARP replies. It would fit if users were reaching fraudulent websites, but the observed one-MAC-to-many-IP ARP mapping indicates ARP spoofing.

  • ✗

    DHCP starvation

    Why it's wrong here

    DHCP starvation exhausts a server's address pool by flooding DHCPDISCOVER requests with spoofed MAC addresses; it does not forge ARP replies binding one MAC to many IPs. It would be the answer if clients were failing to obtain leases, not if ARP mappings were being poisoned.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.