CompTIA
CS0-003 · Question #589
A security analyst reviews the following output: Which of the following malicious activities is occurring?
The correct answer is D. ARP scanning. The repeated ARP requests from the same source MAC address for a sequence of IP addresses (e.g., 172.20.0.1 to 172.20.0.12) indicate ARP scanning. This is typically used to map out live hosts on a network by identifying which IPs respond to ARP requests.
Submitted by fernanda_arg· Mar 6, 2026Security Operations
Question
A security analyst reviews the following output:
Which of the following malicious activities is occurring?
Exhibit
Options
- AARP poisoning
- BMAC flooding
- CARP spoofing
- DARP scanning
How the community answered
(29 responses)- A7% (2)
- B3% (1)
- C17% (5)
- D72% (21)
Explanation
The repeated ARP requests from the same source MAC address for a sequence of IP addresses (e.g., 172.20.0.1 to 172.20.0.12) indicate ARP scanning. This is typically used to map out live hosts on a network by identifying which IPs respond to ARP requests.
Topics
#ARP scanning#network reconnaissance#packet analysis
Community Discussion
No community discussion yet for this question.
