SSCP Network and Communications Security Practice Question
Which of the following is a common defense against ARP spoofing attacks on a local area network?
⚠ Common exam trap
SSCP often tests the distinction between DHCP snooping (filters DHCP) and DAI (filters ARP), so candidates who see 'ARP spoofing' and pick DHCP snooping because it builds the binding table miss that DAI is the enforcement mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dynamic ARP Inspection
Dynamic ARP Inspection (DAI) validates ARP packets on a per-port basis by comparing IP-to-MAC bindings against a trusted DHCP snooping database, dropping ARP packets with invalid bindings. This directly prevents ARP spoofing/poisoning attacks by ensuring only legitimate ARP replies are accepted on untrusted ports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DHCP snooping
Why it's wrong here
DHCP snooping builds a trusted binding of MAC, IP and switch port to block rogue DHCP servers and untrusted DHCP offers; it does not validate ARP replies, so spoofed ARP mappings still poison caches. Dynamic ARP Inspection, which consumes those bindings, is the ARP-specific defence.
- ✗
Port security
Why it's wrong here
Port security restricts which MAC addresses may appear on a switch port, blocking MAC flooding but not forged ARP replies, which are valid-looking frames. It is tempting because it hardens Layer 2 access, and it would be correct for stopping rogue devices or MAC spoofing on access ports.
- ✗
MAC filtering
Why it's wrong here
MAC filtering restricts which hardware addresses may associate with a switch port or access point, but ARP spoofing uses legitimate MACs with falsified IP-to-MAC mappings, so filtering does not detect it. It is appropriate for limiting device access, not for validating ARP traffic.
- ✓
Dynamic ARP Inspection
Why this is correct
Dynamic ARP Inspection intercepts ARP packets on untrusted switch ports and validates each against the DHCP snooping binding table, discarding forged replies that map an attacker's MAC to another host's IP. This directly satisfies the stem's requirement for a LAN-level defence, preventing the cache poisoning that enables man-in-the-middle interception.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.