Courseiva

SSCP Network and Communications Security Practice Question

Which of the following is a common defense against ARP spoofing attacks on a local area network?

⚠ Common exam trap

SSCP often tests the distinction between DHCP snooping (filters DHCP) and DAI (filters ARP), so candidates who see 'ARP spoofing' and pick DHCP snooping because it builds the binding table miss that DAI is the enforcement mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Dynamic ARP Inspection

Dynamic ARP Inspection (DAI) validates ARP packets on a per-port basis by comparing IP-to-MAC bindings against a trusted DHCP snooping database, dropping ARP packets with invalid bindings. This directly prevents ARP spoofing/poisoning attacks by ensuring only legitimate ARP replies are accepted on untrusted ports.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DHCP snooping

    Why it's wrong here

    DHCP snooping builds a trusted binding of MAC, IP and switch port to block rogue DHCP servers and untrusted DHCP offers; it does not validate ARP replies, so spoofed ARP mappings still poison caches. Dynamic ARP Inspection, which consumes those bindings, is the ARP-specific defence.

  • ✗

    Port security

    Why it's wrong here

    Port security restricts which MAC addresses may appear on a switch port, blocking MAC flooding but not forged ARP replies, which are valid-looking frames. It is tempting because it hardens Layer 2 access, and it would be correct for stopping rogue devices or MAC spoofing on access ports.

  • ✗

    MAC filtering

    Why it's wrong here

    MAC filtering restricts which hardware addresses may associate with a switch port or access point, but ARP spoofing uses legitimate MACs with falsified IP-to-MAC mappings, so filtering does not detect it. It is appropriate for limiting device access, not for validating ARP traffic.

  • ✓

    Dynamic ARP Inspection

    Why this is correct

    Dynamic ARP Inspection intercepts ARP packets on untrusted switch ports and validates each against the DHCP snooping binding table, discarding forged replies that map an attacker's MAC to another host's IP. This directly satisfies the stem's requirement for a LAN-level defence, preventing the cache poisoning that enables man-in-the-middle interception.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.